{"api_version":"1","generated_at":"2026-07-23T09:16:33+00:00","cve":"CVE-2005-2405","urls":{"html":"https://cve.report/CVE-2005-2405","api":"https://cve.report/api/cve/CVE-2005-2405.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-2405","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-2405"},"summary":{"title":"CVE-2005-2405","description":"Opera 8.01, when the \"Arial Unicode MS\" font (ARIALUNI.TTF) is installed, does not properly handle extended ASCII characters in the file download dialog box, which allows remote attackers to spoof file extensions and possibly trick users into executing arbitrary code.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-08-01 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-20","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://securitytracker.com/id?1014592","name":"http://securitytracker.com/id?1014592","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"SecurityTracker.com Archives - Opera Error in Processing Extended ASCII Codes Lets Remote Users Spoof File Extensions in the Download Dialog Box","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.opera.com/linux/changelogs/802/","name":"http://www.opera.com/linux/changelogs/802/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Patch"],"title":"Opera 8.02 for Linux Changelog","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/15870","name":"http://secunia.com/advisories/15870","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Patch"],"title":"Secunia - Advisories - Opera Download Dialog Spoofing and \"setRequestHeader()\" Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/14402","name":"http://www.securityfocus.com/bid/14402","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"Opera Web Browser Content-Disposition Header Download Dialog File Extension Spoofing Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21784","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21784","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2005/1251","name":"http://www.vupen.com/english/advisories/2005/1251","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Webmail | OVH- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-2405","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-2405","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"2405","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"opera","cpe5":"opera_browser","cpe6":"8.01","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T22:22:49.133Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"15870","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/15870"},{"name":"14402","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/14402"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.opera.com/linux/changelogs/802/"},{"name":"ADV-2005-1251","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/1251"},{"name":"opera-content-disposition-extension-spoofing(21784)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21784"},{"name":"1014592","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1014592"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-07-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"Opera 8.01, when the \"Arial Unicode MS\" font (ARIALUNI.TTF) is installed, does not properly handle extended ASCII characters in the file download dialog box, which allows remote attackers to spoof file extensions and possibly trick users into executing arbitrary code."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"15870","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/15870"},{"name":"14402","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/14402"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.opera.com/linux/changelogs/802/"},{"name":"ADV-2005-1251","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/1251"},{"name":"opera-content-disposition-extension-spoofing(21784)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21784"},{"name":"1014592","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1014592"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-2405","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Opera 8.01, when the \"Arial Unicode MS\" font (ARIALUNI.TTF) is installed, does not properly handle extended ASCII characters in the file download dialog box, which allows remote attackers to spoof file extensions and possibly trick users into executing arbitrary code."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"15870","refsource":"SECUNIA","url":"http://secunia.com/advisories/15870"},{"name":"14402","refsource":"BID","url":"http://www.securityfocus.com/bid/14402"},{"name":"http://www.opera.com/linux/changelogs/802/","refsource":"CONFIRM","url":"http://www.opera.com/linux/changelogs/802/"},{"name":"ADV-2005-1251","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/1251"},{"name":"opera-content-disposition-extension-spoofing(21784)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/21784"},{"name":"1014592","refsource":"SECTRACK","url":"http://securitytracker.com/id?1014592"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-2405","datePublished":"2005-07-28T04:00:00.000Z","dateReserved":"2005-07-28T00:00:00.000Z","dateUpdated":"2024-08-07T22:22:49.133Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-08-01 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-20","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:opera:opera_browser:8.01:*:*:*:*:*:*:*","matchCriteriaId":"9DF2B21F-7E97-416B-AF5C-35338A254552"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"2405","Ordinal":"1","Title":"CVE-2005-2405","CVE":"CVE-2005-2405","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"2405","Ordinal":"1","NoteData":"Opera 8.01, when the \"Arial Unicode MS\" font (ARIALUNI.TTF) is installed, does not properly handle extended ASCII characters in the file download dialog box, which allows remote attackers to spoof file extensions and possibly trick users into executing arbitrary code.","Type":"Description","Title":"CVE-2005-2405"},{"CveYear":"2005","CveId":"2405","Ordinal":"2","NoteData":"2005-07-28","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"2405","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}