CVE-2005-0918
The NPSVG3.dll ActiveX control for Adobe SVG Viewer 3.02 and earlier, when running on Internet Explorer, allows remote attackers to determine the existence of arbitrary files by setting the src property to the target filename and using Javascript to…
Does this matter?
Lower severity and a low EPSS score (2.36%). Track it; it rarely justifies an emergency change on its own.
Description
The NPSVG3.dll ActiveX control for Adobe SVG Viewer 3.02 and earlier, when running on Internet Explorer, allows remote attackers to determine the existence of arbitrary files by setting the src property to the target filename and using Javascript to determine if the web page immediately stops loading, which indicates whether the file exists or not.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.36% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-203
- Affected
- adobe/svg viewer
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/15255Broken Link, Vendor Advisory
- http://securitytracker.com/id?1013890Broken Link, Third Party Advisory, VDB Entry
- http://www.adobe.com/support/techdocs/323585.htmlBroken Link, Patch
- http://www.hyperdose.com/advisories/H2005-07.txtBroken Link, Exploit, Patch
- http://secunia.com/advisories/15255Broken Link, Vendor Advisory
- http://securitytracker.com/id?1013890Broken Link, Third Party Advisory, VDB Entry
- http://www.adobe.com/support/techdocs/323585.htmlBroken Link, Patch
- http://www.hyperdose.com/advisories/H2005-07.txtBroken Link, Exploit, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.