CVE-2005-0976
Last modified
CVE-2005-0976 is a vulnerability of currently unknown severity. AppleWebKit (WebCore and WebKit), as used in multiple products such as Safari 1.2 and OmniGroup OmniWeb 5.1, allows remote attackers to read arbitrary files via the XMLHttpRequest Javascript component, as demonstrated using automatically mounted disk images and file:// URLs.. EPSS estimates a 1.82% chance of exploitation in the next 30 days.
Description
AppleWebKit (WebCore and WebKit), as used in multiple products such as Safari 1.2 and OmniGroup OmniWeb 5.1, allows remote attackers to read arbitrary files via the XMLHttpRequest Javascript component, as demonstrated using automatically mounted disk images and file:// URLs.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apple | Safari | 1.2 |
| Hmdt | Shiira | 0.93 |
| Omnigroup | Omniweb | 5.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-0976?
How severe is CVE-2005-0976?
How do I fix CVE-2005-0976?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-0970Mac OS X 10.3.9 and earlier allows users to install, create,…
- CVE-2005-0971Stack-based buffer overflow in the semop system call in Mac …
- CVE-2005-0972Integer overflow in the searchfs system call in Mac OS X 10.…
- CVE-2005-0973Unknown vulnerability in the setsockopt system call in Mac O…
- CVE-2005-0974Unknown vulnerability in the nfs_mount call in Mac OS X 10.3…
- CVE-2005-0975Integer signedness error in the parse_machfile function in t…
- CVE-2005-0977The shmem_nopage function in shmem.c for the tmpfs driver in…
- CVE-2005-0978Directory traversal vulnerability in the Object Push service…
- CVE-2005-0979Multiple buffer overflows in RUMBA 7.3 and earlier allow rem…
- CVE-2005-0980PHP remote file inclusion vulnerability in index.php in Alst…
- CVE-2005-0981Multiple cross-site scripting (XSS) vulnerabilities in Alstr…
- CVE-2005-0982Multiple cross-site scripting (XSS) vulnerabilities in Yet A…
Are you affected by CVE-2005-0976?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
