Adobe
Adobe Acrobat Reader: vulnerabilidades y CVE
Adobe Acrobat Reader tiene 1085 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 24 son críticas y 21 figuran en el catálogo de explotación activa de CISA.
CVE1085
Últimos 12 meses13
Críticas24
Explotadas activamente21
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2009-3459 | Alta (8.8) | 87% | ⚠ Explotación activa | 13 oct 2009 | Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as… |
| CVE-2023-21608 | Alta (7.8) | 61% | ⚠ Explotación activa | 18 ene 2023 | Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the… |
| CVE-2023-26369 | Alta (7.8) | 6.7% | ⚠ Explotación activa | 13 sept 2023 | Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the… |
| CVE-2009-4324 | Alta (7.8) | 82% | ⚠ Explotación activa | 15 dic 2009 | Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code… |
| CVE-2011-0609 | Alta (7.8) | 64% | ⚠ Explotación activa | 15 mar 2011 | Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka… |
| CVE-2010-2883 | Alta (7.3) | 81% | ⚠ Explotación activa | 9 sept 2010 | Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service… |
| CVE-2009-1862 | Alta (7.8) | 21% | ⚠ Explotación activa | 23 jul 2009 | Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of… |
| CVE-2008-0655 | Alta (8.8) | 38% | ⚠ Explotación activa | 7 feb 2008 | Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors. |
| CVE-2011-2462 | Crítica (9.8) | 89% | ⚠ Explotación activa | 7 dic 2011 | Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to execute arbitrary code or… |
| CVE-2007-5659 | Alta (7.8) | 87% | ⚠ Explotación activa | 12 feb 2008 | Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be… |
| CVE-2014-0546 | Crítica (9.8) | 22% | ⚠ Explotación activa | 12 ago 2014 | Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context, via unspecified… |
| CVE-2013-2729 | Crítica (9.8) | 67% | ⚠ Explotación activa | 16 may 2013 | Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2727. |
| CVE-2009-0927 | Alta (8.8) | 97% | ⚠ Explotación activa | 19 mar 2009 | Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a crafted argument to the getIcon method of a Collab… |
| CVE-2011-0611 | Alta (8.8) | 99% | ⚠ Explotación activa | 13 abr 2011 | Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before… |
| CVE-2013-0640 | Alta (7.8) | 87% | ⚠ Explotación activa | 14 feb 2013 | Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, as… |
| CVE-2013-0641 | Alta (7.8) | 32% | ⚠ Explotación activa | 14 feb 2013 | Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute arbitrary code via a crafted PDF document, as exploited in the wild in… |
| CVE-2010-0188 | Alta (7.8) | 88% | ⚠ Explotación activa | 22 feb 2010 | Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors. |
| CVE-2008-2992 | Alta (7.8) | 98% | ⚠ Explotación activa | 4 nov 2008 | Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string… |
| CVE-2013-3346 | Crítica (9.8) | 79% | ⚠ Explotación activa | 30 ago 2013 | Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different… |
| CVE-2021-28550 | Alta (8.8) | 52% | ⚠ Explotación activa | 2 sept 2021 | Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Use After Free vulnerability. An unauthenticated attacker could leverage… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-9713 | Media (5.5) | 0.26% | — | 23 jun 2026 | Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure… |
| CVE-2020-9711 | Media (5.5) | 0.26% | — | 23 jun 2026 | Acrobat Reader versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could… |
| CVE-2020-9695 | Alta (7.8) | 0.26% | — | 23 jun 2026 | Acrobat Reader versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the… |
| CVE-2026-47961 | Media (5.5) | 0.26% | — | 9 jun 2026 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to… |
| CVE-2026-47959 | Alta (7.8) | 0.34% | — | 9 jun 2026 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation… |
| CVE-2026-47914 | Alta (7.8) | 0.38% | — | 9 jun 2026 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue… |
| CVE-2026-47913 | Alta (7.8) | 0.38% | — | 9 jun 2026 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue… |
| CVE-2026-47912 | Alta (7.8) | 0.38% | — | 9 jun 2026 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue… |
| CVE-2026-47911 | Alta (7.8) | 0.26% | — | 9 jun 2026 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this… |
| CVE-2025-64899 | Alta (7.8) | 0.50% | — | 9 dic 2025 | Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past… |
| CVE-2025-64787 | Baja (3.3) | 0.45% | — | 9 dic 2025 | Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security… |
| CVE-2025-64786 | Baja (3.3) | 0.43% | — | 9 dic 2025 | Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could result in a Security… |
| CVE-2025-64785 | Alta (7.8) | 0.48% | — | 9 dic 2025 | Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the… |
| CVE-2025-54257 | Alta (7.8) | 0.34% | — | 9 sept 2025 | Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation… |
| CVE-2025-54255 | Media (4) | 0.27% | — | 9 sept 2025 | Acrobat Reader versions 24.001.30254, 20.005.30774, 25.001.20672 and earlier are affected by a Violation of Secure Design Principles vulnerability that could result in a security feature bypass impacting integrity. An… |
| CVE-2025-47112 | Media (5.5) | 0.41% | — | 10 jun 2025 | Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this… |
| CVE-2025-47111 | Media (5.5) | 0.34% | — | 10 jun 2025 | Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this… |
| CVE-2025-43579 | Media (5.5) | 0.20% | — | 10 jun 2025 | Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an Information Exposure vulnerability that could result in a Security feature bypass. An attacker could leverage this… |
| CVE-2025-43578 | Media (5.5) | 0.46% | — | 10 jun 2025 | Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this… |
| CVE-2025-43577 | Alta (7.8) | 0.45% | — | 10 jun 2025 | Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation… |
| CVE-2025-43576 | Alta (7.8) | 0.55% | — | 10 jun 2025 | Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation… |
| CVE-2025-43575 | Alta (7.8) | 0.37% | — | 10 jun 2025 | Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user.… |
| CVE-2025-43574 | Alta (7.8) | 0.45% | — | 10 jun 2025 | Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation… |
| CVE-2025-43573 | Alta (7.8) | 0.45% | — | 10 jun 2025 | Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation… |
| CVE-2025-43550 | Alta (7.8) | 0.45% | — | 10 jun 2025 | Acrobat Reader versions 24.001.30235, 20.005.30763, 25.001.20521 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation… |
| CVE-2025-27174 | Alta (7.8) | 0.35% | — | 11 mar 2025 | Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation… |
| CVE-2025-27164 | Media (5.5) | 0.41% | — | 11 mar 2025 | Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this… |
| CVE-2025-27163 | Media (5.5) | 0.41% | — | 11 mar 2025 | Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this… |
| CVE-2025-27162 | Alta (7.8) | 0.32% | — | 11 mar 2025 | Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current… |
| CVE-2025-27161 | Alta (7.8) | 0.33% | — | 11 mar 2025 | Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.