Adobe Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Adobe products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
97
In CISA KEV
80
Beyond CISA KEV
17
Sensor Observed
2
Virtual Patch Available
2
Adobe KEVs Added by Year
97 Adobe KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2009-0927
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute... |
Reader and Acrobat | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2010-2861
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read... |
ColdFusion | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2016-4171
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as... |
Flash Player | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2016-7892
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField... |
Adobe Flash Player 23.0.0.207 and earlier, 11.2.202.644 and earlier | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2012-2034
Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on... |
Flash Player | Confirmed | In CISA | 28 Mar 2022 |
|
CVE-2013-2729
Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary... |
Reader and Acrobat | Confirmed | In CISA | 28 Mar 2022 |
|
CVE-2014-9163
Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425... |
Flash Player | Confirmed | In CISA | 13 Apr 2022 |
|
CVE-2015-0311
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through... |
Flash Player | Confirmed | In CISA | 13 Apr 2022 |
|
CVE-2015-0313
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before... |
Flash Player | Confirmed | In CISA | 13 Apr 2022 |
|
CVE-2015-3113
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before... |
Flash Player | Confirmed | In CISA | 13 Apr 2022 |
|
CVE-2015-5122
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on... |
Flash Player | Confirmed | In CISA | 13 Apr 2022 |
|
CVE-2015-5123
Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on... |
Flash Player | Confirmed | In CISA | 13 Apr 2022 |
|
CVE-2018-5002
Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to... |
Adobe Flash Player 29.0.0.171 and earlier versions | Confirmed | In CISA | 23 May 2022 |
|
CVE-2014-0546
Adobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows allow attackers to bypass a sandbox protection mechanism, and... |
Reader and Acrobat | Confirmed | In CISA | 25 May 2022 |
|
CVE-2014-8439
Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before... |
Flash Player | Confirmed | In CISA | 25 May 2022 |
|
CVE-2015-8651
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux,... |
Flash Player | Confirmed | In CISA | 25 May 2022 |
|
CVE-2015-0310
Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly... |
Flash Player | Confirmed | In CISA | 25 May 2022 |
|
CVE-2016-0984
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before... |
Flash Player | Confirmed | In CISA | 25 May 2022 |
|
CVE-2016-1010
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on... |
Flash Player | Confirmed | In CISA | 25 May 2022 |
|
CVE-2007-5659
Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long... |
Reader and Acrobat | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2008-0655
Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors. |
Reader and Acrobat | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2009-1862
Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87,... |
["Reader", "Acrobat", "Flash Player"] | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2009-3953
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote... |
Reader and Acrobat | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2009-4324
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on... |
Reader and Acrobat | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2010-1297
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and... |
Flash Player, AIR, Reader, Acrobat | Confirmed | In CISA | 08 Jun 2022 |
Common Vulnerability Classes (CWE)
- CWE-416 — Use After Free 15
- CWE-787 — Out-of-bounds Write 11
- CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 9
- CWE-502 — Deserialization of Untrusted Data 6
- CWE-190 — Integer Overflow or Wraparound 4
- CWE-284 — Improper Access Control 4
- CWE-20 — Improper Input Validation 4
- CWE-121 — Stack-based Buffer Overflow 3
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology