The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.
What this batch was researched, not held
Two annotation findings from the same researcher, reported two weeks apart
This group holds 34 of the 74 records naming Adobe's May 2022 Acrobat and Reader update, all published on 11 May 2022. Two of them can be followed all the way back, because Trend Micro's Zero Day Initiative published its own advisories for them. CVE-2022-28268 is a read past the end of a buffer in the handling of annotation objects, the parts of a document that hold comments, highlights and stamps. CVE-2022-28250 is a use-after-free in the parsing of the same kind of object, where the program acts on an object without first checking it is still there. Both were reported by Mat Powell of the Zero Day Initiative, on 25 February 2022 and 11 March 2022, two weeks apart and into the same area of the program. The Zero Day Initiative published both on 28 April 2022 and both advisories point back to this Adobe update as the fix. Both are rated 3.3 out of 10, which is low: on their own they leak a little memory, and the advisories say an attacker would need to combine one with something else to run code.
These records were published on one day because Adobe ships Reader fixes on a schedule, not because they are one problem. For two of them we can name the researcher, the date he reported it and the part of the program involved. For the other 32 we cannot, and nothing in a record says whether it resembles the two we can.
2022-02-25Mat Powell reports the annotation read past the end of a buffer, later CVE-2022-28268, to Adobe
2022-03-11The same researcher reports the annotation use-after-free, later CVE-2022-28250, two weeks later
2022-04-28The Zero Day Initiative publishes both advisories, each naming this Adobe update as the fix
2022-05-11The 34 records in this group reach the CVE list on one day
The specific gap here is attribution, not description. Adobe's acknowledgements page is not readable to us, so of the 34 records in this group we can name a reporter for two, and only because the Zero Day Initiative published those two itself. Nothing tells you how the other 32 were found, when they were reported, or whether they came from one person or thirty. Nothing here says whether any of them was ever seen in an attack.
Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.
CVE-2022-24101Adobe Acrobat Reader DC Annotation Use-After-Free Information Disclosure VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-24102Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-24103Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-24104Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-27785Adobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-27786Adobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-27787Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityCWE-787 Out-of-bounds Write (CWE-787)
CVE-2022-27788Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityCWE-787 Out-of-bounds Write (CWE-787)
CVE-2022-27789Adobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-27790Adobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-27791Adobe Acrobat Reader DC Font Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityCWE-121 Stack-based Buffer Overflow (CWE-121)
CVE-2022-27792Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityCWE-787 Out-of-bounds Write (CWE-787)
CVE-2022-27793Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityCWE-787 Out-of-bounds Write (CWE-787)
CVE-2022-27794Adobe Acrobat Reader DC Font Parsing Uninitialized Variable Remote Code Execution VulnerabilityCWE-824 Access of Uninitialized Pointer…
CVE-2022-27795Adobe Acrobat Reader DC AcroForm isDefaultChecked Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-27796Adobe Acrobat Reader DC AcroForm isBoxChecked Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-27797Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)