Showing 25 vulnerabilities on this page for Acrobat and Reader

Signals CISA KEV Ransomware Nuclei
Adobe vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') (CWE-1321)

Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CWE-1321Apr 11, 2026
CVSS8.6v3.1EPSS7.09%PoCs4SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Acrobat Reader | Use After Free (CWE-416)

Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CWE-416Sep 13, 2024
CVSS7.8v3.1EPSS2.34%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

[Google Project Zero] Adobe Acrobat DC OOBW 0-day actively exploited in the wild

Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CWE-787Sep 13, 2023
CVSS7.8v3.1EPSS7.04%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

[ZS-VR-22-112] Adobe Acrobat Out-of-bounds Read Memory leak

Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CWE-125Apr 12, 2023
CVSS5.5v3.1EPSS2.94%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Acrobat Reader DC resetForm Use-After-Free Remote Code Execution Vulnerability

Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CWE-416Jan 18, 2023
CVSS7.8v3.1EPSS61.5%PoCs2SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Acrobat Reader use after free vulnerability could lead to arbitrary code execution

Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CWE-416Sep 2, 2021
CVSS8.8v3.1EPSS52%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution

Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CWE-122CWE-787Feb 11, 2021
CVSS8.8v3.1EPSS86.3%PoCs1SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

CWE-787Sep 25, 2018
CVSS9.8v3.0EPSS34.7%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CWE-125Sep 25, 2018
CVSS7.5v3.0EPSS6.73%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CWE-125Sep 25, 2018
CVSS7.5v3.0EPSS6.73%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CWE-125Sep 25, 2018
CVSS7.5v3.0EPSS6.73%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CWE-125Sep 25, 2018
CVSS7.5v3.0EPSS33.6%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

CWE-125Sep 25, 2018
CVSS7.5v3.0EPSS33.6%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Acrobat and Reader Double Free Vulnerability

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Double Free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

CWE-415Jul 9, 2018
CVSS8.8v3.1EPSS36.6%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Acrobat and Reader Out-of-bounds Read

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of XPS font processing. A successful attack can lead to sensitive data exposure.

CWE-125Feb 27, 2018
CVSS6.5v3.0EPSS10.8%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Acrobat and Reader Improper Restriction of Operations within the Bounds of a Memory Buffer

An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a heap overflow vulnerability when processing a JPEG file embedded within an XPS document.

CWE-119Dec 9, 2017
CVSS8.8v3.0EPSS10.7%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Acrobat and Reader Improper Validation of Array Index

An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is a result of untrusted input that is used to calculate an array index; the calculation occurs in the printing functionality. The vulnerability leads to an operation that can write to a memory location that is outside of the memory addresses allocated for the data structure. The spe

CWE-129Dec 9, 2017
CVSS8.8v3.0EPSS6.72%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Reader and Acrobat Sandbox Bypass Vulnerability

Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context, via unspecified vectors.

Aug 12, 2014
CVSS9.8v3.1EPSS22.3%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Reader and Acrobat Use-After-Free Vulnerability

Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors.

CWE-399CWE-416Jan 15, 2014
CVSS8.8v3.1EPSS40.2%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Reader and Acrobat Memory Corruption Vulnerability

Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-201

CWE-119CWE-787Aug 30, 2013
CVSS9.8v3.1EPSS78.6%PoCs3SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability

Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2727.

CWE-189CWE-190May 16, 2013
CVSS9.8v3.1EPSS66.6%PoCs2SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Adobe Reader Buffer Overflow Vulnerability

Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute arbitrary code via a crafted PDF document, as exploited in the wild in February 2013.

CWE-120Feb 14, 2013
CVSS7.8v3.1EPSS32.4%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Reader and Acrobat Memory Corruption Vulnerability

Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, as exploited in the wild in February 2013.

CWE-787Feb 14, 2013
CVSS7.8v3.1EPSS87%PoCs1SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Reader and Acrobat PRC component Remote Code Execution

Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windows, Adobe Reader and Acrobat 9.x through 9.4.6 on Mac OS X, Adobe Reader and Acrobat 10.x through 10.1.1 on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011.

Dec 16, 2011
CVSS10.0v2.0EPSS7.52%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability

Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011.

CWE-787Dec 7, 2011
CVSS9.8v3.1EPSS86.6%PoCs2SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX