{"api_version":"1","generated_at":"2026-07-23T01:50:53+00:00","cve":"CVE-2005-1306","urls":{"html":"https://cve.report/CVE-2005-1306","api":"https://cve.report/api/cve/CVE-2005-1306.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-1306","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-1306"},"summary":{"title":"CVE-2005-1306","description":"The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the \"XML External Entity vulnerability.\"","state":"PUBLISHED","assigner":"mitre","published_at":"2005-06-15 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-611","n/a"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.adobe.com/support/techdocs/331710.html","name":"http://www.adobe.com/support/techdocs/331710.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Patch","Vendor Advisory"],"title":"XML External Entity vulnerability (Adobe Reader and Acrobat) - Support Knowledgebase","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/13962","name":"http://www.securityfocus.com/bid/13962","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Exploit","Patch","Third Party Advisory","VDB Entry","Vendor Advisory"],"title":"Adobe Acrobat/Adobe Reader File Existence and Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-1306","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-1306","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"1306","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"acrobat","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1306","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"acrobat","cpe6":"7.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1306","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"acrobat_reader","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1306","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"acrobat_reader","cpe6":"7.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2005-1306","organization":"Red Hat","lastmodified":"2006-08-30","contributor":"Mark J Cox","statementText":"Not vulnerable. Adobe told us this issue did not affect the Linux version of Adobe Reader.","cve_year":"2005","cve_id":"1306","crc32":"5fc0e8a7"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T21:44:06.170Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"13962","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/13962"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.adobe.com/support/techdocs/331710.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-06-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the \"XML External Entity vulnerability.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2021-06-15T16:41:34.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"13962","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/13962"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.adobe.com/support/techdocs/331710.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-1306","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the \"XML External Entity vulnerability.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"13962","refsource":"BID","url":"http://www.securityfocus.com/bid/13962"},{"name":"http://www.adobe.com/support/techdocs/331710.html","refsource":"CONFIRM","url":"http://www.adobe.com/support/techdocs/331710.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-1306","datePublished":"2005-06-15T04:00:00.000Z","dateReserved":"2005-04-27T00:00:00.000Z","dateUpdated":"2024-08-07T21:44:06.170Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-06-15 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-611","n/a"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:acrobat:7.0:*:*:*:*:*:*:*","matchCriteriaId":"FECFC942-4F04-420C-A9B4-AE0C0590317F"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:acrobat:7.0.1:*:*:*:*:*:*:*","matchCriteriaId":"F81817F2-1E3A-4A52-88F1-6B614A2A1F0A"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:acrobat_reader:7.0:*:*:*:*:*:*:*","matchCriteriaId":"6E2D0266-6954-4DBA-9EEE-8BF73B39DD61"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:acrobat_reader:7.0.1:*:*:*:*:*:*:*","matchCriteriaId":"24262AFA-2EC8-479E-8922-36DB4243E404"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"1306","Ordinal":"1","Title":"CVE-2005-1306","CVE":"CVE-2005-1306","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"1306","Ordinal":"1","NoteData":"The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the \"XML External Entity vulnerability.\"","Type":"Description","Title":"CVE-2005-1306"},{"CveYear":"2005","CveId":"1306","Ordinal":"2","NoteData":"2005-06-15","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"1306","Ordinal":"3","NoteData":"2021-06-15","Type":"Other","Title":"Modified"}]}}}