CVE-2005-0918
The NPSVG3.dll ActiveX control for Adobe SVG Viewer 3.02 and earlier, when running on Internet Explorer, allows remote attackers to determine the existence of arbitrary files by setting the src property to the target filename and using Javascript to determine if the web page immediately stops loading, which indicates whether the file exists or not.
Published
2005-05-05T04:00:00.000
Last Modified
2025-04-03T01:03:51.193
Status
Deferred
Source
[email protected]
Severity
CVSSv2: 5.0 (MEDIUM)
CVSSv2 Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
- Access Vector: NETWORK
- Access Complexity: LOW
- Authentication: NONE
- Confidentiality Impact: PARTIAL
- Integrity Impact: NONE
- Availability Impact: NONE
Exploitability Score
10.0
Impact Score
2.9
Weaknesses
Affected Vendors & Products
References
-
http://secunia.com/advisories/15255
Broken Link, Vendor Advisory
([email protected])
-
http://securitytracker.com/id?1013890
Broken Link, Third Party Advisory, VDB Entry
([email protected])
-
http://www.adobe.com/support/techdocs/323585.html
Broken Link, Patch
([email protected])
-
http://www.hyperdose.com/advisories/H2005-07.txt
Broken Link, Exploit, Patch
([email protected])
-
http://secunia.com/advisories/15255
Broken Link, Vendor Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
http://securitytracker.com/id?1013890
Broken Link, Third Party Advisory, VDB Entry
(af854a3a-2127-422b-91ae-364da2661108)
-
http://www.adobe.com/support/techdocs/323585.html
Broken Link, Patch
(af854a3a-2127-422b-91ae-364da2661108)
-
http://www.hyperdose.com/advisories/H2005-07.txt
Broken Link, Exploit, Patch
(af854a3a-2127-422b-91ae-364da2661108)