Vulnerability Description
The Acrobat web control in Adobe Acrobat and Acrobat Reader 7.0 and earlier, when used with Internet Explorer, allows remote attackers to determine the existence of arbitrary files via the LoadFile ActiveX method.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Acrobat Reader | 4.5 |
References
- http://secunia.com/advisories/14813
- http://www.adobe.com/support/techdocs/331465.html
- http://www.hyperdose.com/advisories/H2005-06.txt
- http://www.niscc.gov.uk/niscc/docs/re-20050401-00264.pdf
- http://www.osvdb.org/15242
- http://www.securityfocus.com/bid/12989
- http://www.vupen.com/english/advisories/2005/0310
- http://secunia.com/advisories/14813
- http://www.adobe.com/support/techdocs/331465.html
- http://www.hyperdose.com/advisories/H2005-06.txt
- http://www.niscc.gov.uk/niscc/docs/re-20050401-00264.pdf
- http://www.osvdb.org/15242
- http://www.securityfocus.com/bid/12989
- http://www.vupen.com/english/advisories/2005/0310
FAQ
What is CVE-2005-0035?
CVE-2005-0035 is a vulnerability with a CVSS score of 5.1 (MEDIUM). The Acrobat web control in Adobe Acrobat and Acrobat Reader 7.0 and earlier, when used with Internet Explorer, allows remote attackers to determine the existence of arbitrary files via the LoadFile Ac...
How severe is CVE-2005-0035?
CVE-2005-0035 has been rated MEDIUM with a CVSS base score of 5.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-0035?
Check the references section above for vendor advisories and patch information. Affected products include: Adobe Acrobat Reader.