Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2021-38373
In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" …
Kmail
Mitigation only
MEDIUM 5.5
CVE-2020-13152
A remote user can create a specially crafted M3U file, media playlist file that when loaded by the target user, will trigger a memory leak, whereby A…
Amarok
No fix yet
MEDIUM 5.5
CVE-2013-2213
The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addons uses the GNU C Library rand function's linear congruential generato…
Paste Applet
No fix yet
MEDIUM 6.8
CVE-2012-4515EPSS 6%
Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, allows remote attacker…
Kde
No fix yet
MEDIUM 6.4
CVE-2012-4513EPSS 13%
khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via l…
Kde
No fix yet
MEDIUM 6.9
CVE-2011-5054
kcheckpass passes a user-supplied argument to the pam_start function, often within a setuid environment, which allows local users to invoke any confi…
Kcheckpass
Mitigation only
MEDIUM 6.4
CVE-2010-1511
KGet 2.4.2 in KDE SC 4.0.0 through 4.4.3 does not properly request download confirmation from the user, which makes it easier for remote attackers to…
Kget
Mitigation only
MEDIUM 5.8
CVE-2010-1000
Directory traversal vulnerability in KGet in KDE SC 4.0.0 through 4.4.3 allows remote attackers to create arbitrary files via directory traversal seq…
Kde Sc
Mitigation only
HIGH 7.5
CVE-2009-2702
KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.50…
Kdelibs
Mitigation only
MEDIUM 5.0
CVE-2008-5712
The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via (1) a long COLOR attribute in an …
Konqueror
No fix yet
MEDIUM 5.0
CVE-2008-4382
Konqueror in KDE 3.5.9 allows remote attackers to cause a denial of service (application crash) via Javascript that calls the alert function with a U…
Konqueror
Mitigation only
MEDIUM 6.8
CVE-2007-4225
Visual truncation vulnerability in KDE Konqueror 3.5.7 allows remote attackers to spoof the URL address bar via an http URI with a large amount of wh…
Konqueror
Mitigation only
MEDIUM 6.4
CVE-2007-3143
Visual truncation vulnerability in Konqueror 3.5.5 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a long …
Konqueror
No fix yet
MEDIUM 5.0
CVE-2007-2164
Konqueror 3.5.5 release 45.4 allows remote attackers to cause a denial of service (browser crash or abort) via JavaScript that matches a regular expr…
Konqueror
Mitigation only
HIGH 7.8
CVE-2007-1565
Konqueror 3.5.5 allows remote attackers to cause a denial of service (crash) by using JavaScript to read a child iframe having an ftp:// URI.
Konqueror
Mitigation only
MEDIUM 6.8
CVE-2007-1564
The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to connect to other servers, perform a proxied port scan…
Konqueror
Mitigation only
HIGH 7.8
CVE-2007-1265
KMail 1.9.5 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents KMail from visually distinguishing between…
K Mail
Mitigation only
MEDIUM 5.0
CVE-2006-6297
Stack consumption vulnerability in the KFILE JPEG (kfile_jpeg) plugin in kdegraphics 3, as used by konqueror, digikam, and other KDE image browsers, …
Kdegraphics
Mitigation only
MEDIUM 6.4
CVE-2005-4684
Konqueror can associate a cookie with multiple domains when the DNS resolver has a non-root domain in its search list, which allows remote attackers …
Konqueror
Mitigation only
HIGH 7.5
CVE-2004-1165
Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FT…
Kdelibs
Mitigation only
MEDIUM 5.0
CVE-2004-0870
KDE Konqueror does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the sa…
Konqueror
Mitigation only
MEDIUM 5.0
CVE-2004-0527EPSS 6%
KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that poi…
Konqueror
No fix yet
HIGH 7.5
CVE-2004-0721
Konqueror 3.1.3, 3.2.2, and possibly other versions does not properly prevent a frame in one domain from injecting content into a frame that belongs …
Konqueror
Mitigation only
HIGH 7.5
CVE-2003-0256
The GnuPG plugin in kopete before 0.6.2 does not properly cleanse the command line when executing gpg, which allows remote attackers to execute arbit…
Kopete
Mitigation only
HIGH 7.2
CVE-2000-0460
Buffer overflow in KDE kdesud on Linux allows local uses to gain privileges via a long DISPLAY environmental variable.
Kde
No fix yet
HIGH 7.2
CVE-2000-0393
The KDE kscd program does not drop privileges when executing a program specified in a user's SHELL environmental variable, which allows the user to g…
Kde
Mitigation only
HIGH 7.2
CVE-1999-1107
Buffer overflow in kppp in KDE allows local users to gain root access via a long PATH environmental variable.
Kde
Mitigation only
HIGH 7.2
CVE-1999-1096
Buffer overflow in kscreensaver in KDE klock allows local users to gain root privileges via a long HOME environmental variable.
Kde
Mitigation only
HIGH 7.2
CVE-1999-1106
Buffer overflow in kppp in KDE allows local users to gain root access via a long -c (account_name) command line argument.
Kde
No fix yet
MEDIUM 5.0
CVE-1999-1267
KDE file manager (kfm) uses a TCP server for certain file operations, which allows remote attackers to modify arbitrary files by sending a copy comma…
Kde
Mitigation only