Back

CVE-2005-1306

HIGH

The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulnerability."

Published: Jun 15, 2005 Modified: Jun 16, 2026
CWE-611

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: NONE Availability Impact: NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products (4)

Vendor Product Version
adobe acrobat 7.0
adobe acrobat 7.0.1
adobe acrobat_reader 7.0
adobe acrobat_reader 7.0.1

GitHub Security Advisory GHSA-jrv6-p293-phjx

The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to...

References (4)

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 14.53%

Top 4% most likely to be exploited

Threat Score 34.4 / 100

Data Sources

NVD EPSS GitHub