MEDIUM · 5.0

CVE-2005-0918

The NPSVG3.dll ActiveX control for Adobe SVG Viewer 3.02 and earlier, when running on Internet Explorer, allows remote attackers to determine the existence of arbitrary files by setting the src proper...

Vulnerability Description

The NPSVG3.dll ActiveX control for Adobe SVG Viewer 3.02 and earlier, when running on Internet Explorer, allows remote attackers to determine the existence of arbitrary files by setting the src property to the target filename and using Javascript to determine if the web page immediately stops loading, which indicates whether the file exists or not.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
AdobeSvg Viewer<= 3.02
MicrosoftInternet Explorer-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2005-0918?

CVE-2005-0918 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The NPSVG3.dll ActiveX control for Adobe SVG Viewer 3.02 and earlier, when running on Internet Explorer, allows remote attackers to determine the existence of arbitrary files by setting the src proper...

How severe is CVE-2005-0918?

CVE-2005-0918 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-0918?

Check the references section above for vendor advisories and patch information. Affected products include: Adobe Svg Viewer, Microsoft Internet Explorer.