CVE-2005-0918
Estado: ModificadaMedia (5)—
The NPSVG3.dll ActiveX control for Adobe SVG Viewer 3.02 and earlier, when running on Internet Explorer, allows remote attackers to determine the existence of arbitrary files by setting the src property to the target filename and using Javascript to determine if the web page immediately stops loading, which indicates whether the file exists or not.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.36%
- Percentil entre todas las CVEs puntuadas: 83
- Fecha de la puntuación: 9/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-203
Referencias
- http://secunia.com/advisories/15255
- http://securitytracker.com/id?1013890
- http://www.adobe.com/support/techdocs/323585.html
- http://www.hyperdose.com/advisories/H2005-07.txt
- http://secunia.com/advisories/15255
- http://securitytracker.com/id?1013890
- http://www.adobe.com/support/techdocs/323585.html
- http://www.hyperdose.com/advisories/H2005-07.txt
JSON original (NVD)
Mostrar
{
"id": "CVE-2005-0918",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2005-05-05T04:00:00.000",
"references": [
{
"url": "http://secunia.com/advisories/15255",
"tags": [
"Broken Link",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1013890",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.adobe.com/support/techdocs/323585.html",
"tags": [
"Broken Link",
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.hyperdose.com/advisories/H2005-07.txt",
"tags": [
"Broken Link",
"Exploit",
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/15255",
"tags": [
"Broken Link",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securitytracker.com/id?1013890",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.adobe.com/support/techdocs/323585.html",
"tags": [
"Broken Link",
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.hyperdose.com/advisories/H2005-07.txt",
"tags": [
"Broken Link",
"Exploit",
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-203"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The NPSVG3.dll ActiveX control for Adobe SVG Viewer 3.02 and earlier, when running on Internet Explorer, allows remote attackers to determine the existence of arbitrary files by setting the src property to the target filename and using Javascript to determine if the web page immediately stops loading, which indicates whether the file exists or not."
}
],
"lastModified": "2026-06-16T22:12:02.947",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:adobe:svg_viewer:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9C1FE08B-07BF-4393-AC21-26590D219EE6",
"versionEndIncluding": "3.02"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C37BA825-679F-4257-9F2B-CE2318B75396"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}