VendorsAdobeacrobat_readerany version
Vulnerabilities

Adobe Acrobat Reader any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

766CVEs
CVE-2009-1862
Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009.
Published 2009-07-23 · Analyzed
9.3KEVEPSS 0.212
CVE-2009-2994
Buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 might allow attackers to execute arbitrary code via unspecified vectors.
Published 2009-10-19 · Modified
9.31 PoCEPSS 0.186
CVE-2022-27791
Adobe Acrobat Reader DC Font Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.178
CVE-2022-27799
Adobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.177
CVE-2017-16393
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the JavaScript engine. The mismatch between an old and a new object can provide an attacker with unintended memory access -- potentially leading to code corruption, control-flow hijack, or an information leak attack. Successful exploitation could lead to arbitrary code execution.
Published 2017-12-09 · Modified
9.3EPSS 0.169
CVE-2021-45062
Adobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-01-14 · Modified
9.3EPSS 0.165
CVE-2020-24433
Adobe Acrobat Reader DC Local Privilege Escalation via Installer Component
Published 2020-11-05 · Modified
9.3EPSS 0.159
CVE-2010-2884
Adobe Flash Player 10.1.82.76 and earlier on Windows, Mac OS X, Linux, and Solaris and 10.1.92.10 on Android; authplay.dll in Adobe Reader and Acrobat 9.x before 9.4; and authplay.dll in Adobe Reader and Acrobat 8.x before 8.2.5 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in September 2010.
Published 2010-09-15 · Modified
9.3EPSS 0.156
CVE-2017-11241
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable heap overflow vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to polygons. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
9.3EPSS 0.147
CVE-2017-11220
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable heap overflow vulnerability in an internal data structure. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
9.3EPSS 0.147
CVE-2008-0726
Integer overflow in Adobe Reader and Acrobat 8.1.1 and earlier allows remote attackers to execute arbitrary code via crafted arguments to the printSepsWithParams, which triggers memory corruption.
Published 2008-02-12 · Modified
9.3EPSS 0.146
CVE-2022-27794
Adobe Acrobat Reader DC Font Parsing Uninitialized Variable Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.143
CVE-2007-5663
Adobe Reader and Acrobat 8.1.1 and earlier allows remote attackers to execute arbitrary code via a crafted PDF file that calls an insecure JavaScript method in the EScript.api plug-in. NOTE: this issue might be subsumed by CVE-2008-0655.
Published 2008-02-12 · Modified
9.3EPSS 0.133
CVE-2017-16368
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability leads to a stack-based buffer overflow condition in the internal Unicode string manipulation module. It is triggered by an invalid PDF file, where a crafted Unicode string causes an out of bounds memory access of a stack allocated buffer, due to improper checks when manipulating an offset of a pointer to the buffer. Attackers can exploit the vulnerability and achieve arbitrary code execution if they can effectively control the accessible memory.
Published 2017-12-09 · Modified
9.3EPSS 0.132
CVE-2017-16396
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer access with an incorrect length value in the TIFF processing module. Crafted input causes a mismatch between allocated buffer size and the access allowed by the computation. If an attacker can adequately control the accessible memory then this vulnerability can be leveraged to achieve arbitrary code execution.
Published 2017-12-09 · Modified
9.3EPSS 0.128
CVE-2017-16395
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer access with an incorrect length value in the image conversion module when processing Enhanced Metafile Format (EMF). Crafted EMF input (EMR_STRETCHDIBITS) causes a mismatch between allocated buffer size and the access allowed by the computation. If an attacker can adequately control the accessible memory then this vulnerability can be leveraged to achieve arbitrary code execution.
Published 2017-12-09 · Modified
9.3EPSS 0.128
CVE-2017-16392
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer access with an incorrect length value in the JPEG processing module. Crafted input with an unexpected JPEG file segment size causes a mismatch between allocated buffer size and the access allowed by the computation. If an attacker can adequately control the accessible memory then this vulnerability can be leveraged to achieve arbitrary code execution.
Published 2017-12-09 · Modified
9.3EPSS 0.128
CVE-2017-16381
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer access with an incorrect length value when processing TIFF files embedded within an XPS document. Crafted TIFF image input causes a mismatch between allocated buffer size and the access allowed by the computation. If an attacker can adequately control the accessible memory then this vulnerability can be leveraged to achieve arbitrary code execution.
Published 2017-12-09 · Modified
9.3EPSS 0.128
CVE-2017-16385
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer access with an incorrect length value in TIFF parsing during XPS conversion. Crafted TIFF image input causes a mismatch between allocated buffer size and the access allowed by the computation. If an attacker can adequately control the accessible memory then this vulnerability can be leveraged to achieve arbitrary code execution.
Published 2017-12-09 · Modified
9.3EPSS 0.128
CVE-2017-11259
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private data. Successful exploitation could lead to arbitrary code execution.
Published 2017-08-11 · Modified
9.3EPSS 0.128
CVE-2022-24102
Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.126
CVE-2022-28233
Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.125
CVE-2022-28232
Adobe Acrobat Reader DC Collab Object Use-After-Free Information Disclosure Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.125
CVE-2022-27785
Adobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.125
CVE-2022-28230
Adobe Acrobat Reader DC AcroForm calculateNow Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.125
CVE-2022-27796
Adobe Acrobat Reader DC AcroForm isBoxChecked Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.125
CVE-2022-28240
Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.125
CVE-2009-2983
Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.
Published 2009-10-19 · Modified
9.31 PoCEPSS 0.122
CVE-2022-27786
Adobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.121
CVE-2022-27790
Adobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.119
CVE-2022-28238
Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.119
CVE-2008-4814
Unspecified vulnerability in a JavaScript method in Adobe Reader and Acrobat 8.1.2 and earlier, and before 7.1.1, allows remote attackers to execute arbitrary code via unknown vectors, related to an "input validation issue."
Published 2008-11-05 · Modified
9.3EPSS 0.119
CVE-2022-28236
Adobe Acrobat Reader DC Annotation Out-Of-Bounds Write Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.116
CVE-2021-44710
Adobe Acrobat Reader Use-after-free could lead to Arbitrary code execution
Published 2022-01-14 · Modified
9.3EPSS 0.116
CVE-2017-16416
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a computation that writes data past the end of the intended buffer; the computation is part of the image conversion module that handles Enhanced Metafile Format Plus (EMF+) data. The vulnerability is a result of an out of range pointer offset that is used to access sub-elements of an internal data structure. An attacker can potentially leverage the vulnerability to corrupt sensitive data or execute arbitrary code.
Published 2017-12-09 · Modified
9.3EPSS 0.112
CVE-2017-16415
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a computation that writes data past the end of the intended buffer; the computation is a part of the functionality that handles font encodings. The vulnerability is a result of out of range pointer offset that is used to access sub-elements of an internal data structure. An attacker can potentially leverage the vulnerability to corrupt sensitive data or execute arbitrary code.
Published 2017-12-09 · Modified
9.3EPSS 0.112
CVE-2017-16413
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a computation that writes data past the end of the intended buffer; the computation is part of the XPS to PDF conversion module, when processing TIFF files. The vulnerability is a result of an out of range pointer offset that is used to access sub-elements of an internal data structure. An attacker can potentially leverage the vulnerability to corrupt sensitive data or execute arbitrary code.
Published 2017-12-09 · Modified
9.3EPSS 0.112
CVE-2022-24104
Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.111
CVE-2009-1061
Unspecified vulnerability in Adobe Acrobat Reader 9 before 9.1, 8 before 8.1.4, and 7 before 7.1.1 might allow remote attackers to execute arbitrary code via unknown attack vectors related to JBIG2 and "input validation," a different vulnerability than CVE-2009-0193 and CVE-2009-1062.
Published 2009-03-25 · Modified
9.3EPSS 0.110
CVE-2022-28243
Adobe Acrobat Reader DC Doc Object Out-Of-Bounds Read Remote Code Execution Vulnerability
Published 2022-05-11 · Modified
9.3EPSS 0.110
← Prev3 / 20Next →