Adobe Acrobat and Reader: 68 records in one advisory
68 records announced together, published 2019-10-17, every one of them citing the same advisory.
The advisory
Every record in this batch cites https://helpx.adobe.com/security/products/acrobat/apsb19-49.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.
What the records offer
No record in this batch publishes a fixed version in held sources.
No record in this batch is listed by CISA in held sources.
4 of 68 records name something of its own. For the other 64, held sources say the same thing about each.
Most commonly mapped weakness across the batch: Use After Free.
What this page does not cover
Every record citing this advisory is on this page.
The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.
What this batch was researched, not held
68 findings in one October 2019 bundle, one of them a third visit to the same code
Adobe published this Acrobat and Reader update on 15 October 2019 at priority 2, with 68 identifiers in its table: 45 rated critical and 23 important, fixed in 2019.021.20047, 2017.011.30150 and 2015.006.30504. The classes are memory safety almost throughout, led by 26 use-after-free entries and 21 out-of-bounds reads. Twenty-seven credit lines cover 66 of the 68, and two identifiers carry no credit at all. One entry stands apart because its reporter published a technical account of it. CVE-2019-8183 is credited in the bulletin to Aleksandar Nikolic of Cisco Talos, and Talos titled its own report "Adobe Acrobat Reader DC text field value remote code execution vulnerability redux". Talos classes it as an unexpected sign extension in the handling of a text field's value, says it reported the issue on 22 July 2019, and names two of its own earlier reports, TALOS-2018-0704 and TALOS-2019-0774, as the same problem, writing that it "wasn't properly patched to cover all cases".
These are separate findings from separate reporters that Adobe held for one scheduled release, so the record you are reading is its own. One of them is a repeat: Talos says the same text field code had been reported twice before and that the earlier fixes did not cover every case, which is Talos speaking about its own three reports and not about the other 67 records here. The publication date tells you when Adobe shipped, not when anyone found the problem.
Two of the 68 identifiers carry no acknowledgement at all, so nothing says who reported them. Only one of the 27 reporters published a technical write-up, which means that for the other 67 records a bug class and an impact is the whole of the technical content. Adobe names no affected file or function anywhere in the bulletin.
Written from web.archive.org, talosintelligence.com, cveawg.mitre.org, helpx.adobe.com. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.
Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.
68 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.