Back
CVE-2005-1306
HIGH
The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulnerability."
Published: Jun 15, 2005
Modified: Jun 16, 2026
CWE-611
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
NONE
Availability Impact:
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products (4)
| Vendor | Product | Version |
|---|---|---|
| adobe | acrobat | 7.0 |
| adobe | acrobat | 7.0.1 |
| adobe | acrobat_reader | 7.0 |
| adobe | acrobat_reader | 7.0.1 |
GitHub Security Advisory GHSA-jrv6-p293-phjx
The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to...
References (4)
- http://www.adobe.com/support/techdocs/331710.html Broken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/13962 Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.adobe.com/support/techdocs/331710.html Broken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/13962 Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
14.53%
Top 4% most likely to be exploited
Threat Score
34.4 / 100
Data Sources
NVD
EPSS
GitHub