CVE-2005-0035: Medium severity Adobe Acrobat reader vulnerability
Published Apr 21, 2005
·Updated
The Acrobat web control in Adobe Acrobat and Acrobat Reader 7.0 and earlier, when used with Internet Explorer, allows remote attackers to determine the existence of arbitrary files via the LoadFile ActiveX method.
Affected Software
9 affected components
Adobe Acrobat reader=4.5
Adobe Acrobat reader=5.0
Adobe Acrobat reader=5.0.5
Adobe Acrobat reader=5.1
Adobe Acrobat reader=6.0
Adobe Acrobat reader=6.0.1
Adobe Acrobat reader=6.0.2
Adobe Acrobat reader=6.0.3
Adobe Acrobat reader=7.0
Event History
Apr 21, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0035?
CVE-2005-0035 is considered a moderate severity vulnerability as it allows remote attackers to determine the existence of arbitrary files.
2
How do I fix CVE-2005-0035?
To fix CVE-2005-0035, upgrade to a version of Adobe Acrobat Reader later than 7.0.
3
Which versions of Adobe Acrobat Reader are affected by CVE-2005-0035?
CVE-2005-0035 affects Adobe Acrobat Reader versions 4.5 through 7.0.
4
What exploit does CVE-2005-0035 leverage?
CVE-2005-0035 leverages the LoadFile ActiveX method in the Acrobat web control.
5
Can CVE-2005-0035 be exploited remotely?
Yes, CVE-2005-0035 can be exploited remotely due to its reliance on ActiveX controls in Internet Explorer.