peter bassill · operator
$ cve CVE-2005-1306 JSON

CVE-2005-1306 EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 14.5% (pctl 97)

Patch early

A public exploit exists.

Description

The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulnerability."

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS14.53% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-611
On CISA KEVno
Public exploityes
Published2005-06-15
Last modified2026-06-16

Affected (2)

VendorProduct
adobeacrobat
adobeacrobat reader

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD