Vulnerabilities > Adobe > Acrobat Reader > 8.1.7

DATE CVE VULNERABILITY TITLE RISK
2010-04-14 CVE-2010-0191 Code Injection vulnerability in Adobe Acrobat and Acrobat Reader
Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to execute arbitrary code via unspecified vectors, related to a "prefix protocol handler vulnerability."
network
adobe apple microsoft CWE-94
critical
9.3
2010-04-14 CVE-2010-0190 Cross-Site Scripting vulnerability in Adobe Acrobat and Acrobat Reader
Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
4.3
2010-04-05 CVE-2010-1241 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Adobe Acrobat Reader
Heap-based buffer overflow in the custom heap management system in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, aka FG-VD-10-005.
network
adobe apple microsoft CWE-119
critical
9.3
2010-04-05 CVE-2009-4764 Code Injection vulnerability in Adobe Acrobat Reader
Adobe Reader 8.x and 9.x on Windows is able to execute EXE files that are embedded in a PDF document, which makes it easier for remote attackers to trick users into executing arbitrary code via a crafted document.
network
adobe microsoft CWE-94
critical
9.3
2010-02-22 CVE-2010-0188 Code Injection vulnerability in Adobe Acrobat Reader
Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.
network
adobe CWE-94
critical
9.3
2010-02-15 CVE-2010-0186 Cross Domain Scripting vulnerability in Multiple Adobe Products
Cross-domain vulnerability in Adobe Flash Player before 10.0.45.2, Adobe AIR before 1.5.3.9130, and Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows remote attackers to bypass intended sandbox restrictions and make cross-domain requests via unspecified vectors.
network
adobe
6.8
2010-01-13 CVE-2009-3959 Numeric Errors vulnerability in Adobe Acrobat and Acrobat Reader
Integer overflow in the U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a malformed PDF document.
network
low complexity
adobe apple microsoft unix CWE-189
critical
10.0
2010-01-13 CVE-2009-3958 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Adobe Acrobat and Acrobat Reader
Multiple stack-based buffer overflows in the NOS Microsystems getPlus Helper ActiveX control before 1.6.2.49 in gp.ocx in the Download Manager in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow remote attackers to execute arbitrary code via unspecified initialization parameters.
network
low complexity
adobe apple microsoft unix CWE-119
critical
10.0
2010-01-13 CVE-2009-3957 Denial of Service vulnerability in Adobe Reader and Acrobat Null Pointer Dereference
Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow attackers to cause a denial of service (NULL pointer dereference) via unspecified vectors.
network
low complexity
adobe apple microsoft unix
5.0
2010-01-13 CVE-2009-3956 Configuration vulnerability in Adobe Acrobat and Acrobat Reader
The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhanced Security feature, which has unspecified impact and attack vectors, related to a "script injection vulnerability," as demonstrated by Acrobat Forms Data Format (FDF) behavior that allows cross-site scripting (XSS) by user-assisted remote attackers.
network
low complexity
adobe apple microsoft unix CWE-16
critical
10.0