Acrobat Reader

Vendor:

First CVE: Sep 27, 1999 · Active for 26 years

1,137
Total CVEs
More Total CVEs than 100% of tracked products
42.1
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 63% of tracked products
1.9%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Acrobat Reader over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 27, 1999
26 years ago
Most Recent CVE
Jul 17, 2026
7 days ago

CVE Severity & Scoring

Acrobat Reader1,137 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local435 (38.3%)
Network221 (19.4%)
Unknown481 (42.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low651 (57.3%)
High5 (0.4%)
Unknown481 (42.3%)
User Interaction
None39 (3.4%)
Unknown481 (42.3%)
Required617 (54.3%)
Privileges Required
Low16 (1.4%)
High0 (0.0%)
None640 (56.3%)
Unknown481 (42.3%)

Top CVEs

Signals from CVEs in this product scope (1137 CVEs).

1,137 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote att
Dec 7, 20119.898YESYES
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib
Apr 13, 20118.898YESYES
Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute ar
Feb 22, 20107.898YESYES
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a crafted argu
Mar 19, 20098.898YESYES
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript fun
Nov 4, 20087.898YESYES
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) vi
Aug 30, 20139.897YESYES
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary c
Sep 9, 20107.397YESYES
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remo
Dec 15, 20097.897YESYES
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF fi
Oct 13, 20098.897YESYES
Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScrip
Feb 12, 20087.897YESYES

Exploit Exposure

Signals from CVEs in this product scope (1137 CVEs).

CISA KEV
22 CVEs
1.9% of CVEs· 96th percentile
Metasploit
17 CVEs
1.5% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
44 CVEs
3.9% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (1137 CVEs).

Media Mentions

Signals from CVEs in this product scope (1137 CVEs).

Top CNAs Publishing CVEs For Acrobat Reader

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.5.4249.88.2%01
9.5.3249.88.2%01
9.5.2539.87.6%01
9.5.1739.88.5%01
9.5769.88.6%01
9.4.7769.88.6%01
9.4.6779.88.6%01
9.4.5779.88.6%01
9.4.41019.67.9%01
9.4.31029.67.8%01
9.4.21029.67.8%01
9.4.11309.38.9%01
9.41329.39.4%03
9.3.41539.39.1%04
9.3.31559.39.2%05
9.3.21699.38.9%07
9.3.11859.29.0%08
9.3.019.33.5%00
9.31859.28.7%07
9.21869.28.6%07