Vulnerability index

Browse CVEs

99 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kde MEDIUM 5.0
CVE-2012-4514EPSS 10%

rendering/render_replaced.cpp in Konqueror in KDE before 4.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a …

Fix: after 4.9.2
Fix from $1,600 2012-11-11
Koffice HIGH 7.5
CVE-2012-3455EPSS 5%

Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in KOffice 2.3.3 and ea…

Fix: after 2.3.3
Fix from $1,950 2012-08-20
Kcheckpass MEDIUM 6.9
CVE-2011-5054

kcheckpass passes a user-supplied argument to the pam_start function, often within a setuid environment, which allows local users to invoke any confi…

Mitigation only
Fix from $1,600 2012-01-06
Kde Sc MEDIUM 5.8
CVE-2011-1586

Directory traversal vulnerability in the KGetMetalink::File::isValidNameAttr function in ui/metalinkcreator/metalinker.cpp in KGet in KDE SC 4.6.2 an…

Fix: after 4.6.2
Fix from $1,600 2011-04-27
Kde Sc MEDIUM 6.8
CVE-2010-2575

Heap-based buffer overflow in the RLE decompression functionality in the TranscribePalmImageToJPEG function in generators/plucker/inplug/image.cpp in…

Patch available
Fix from $1,600 2010-08-30
Kget MEDIUM 6.4
CVE-2010-1511

KGet 2.4.2 in KDE SC 4.0.0 through 4.4.3 does not properly request download confirmation from the user, which makes it easier for remote attackers to…

Mitigation only
Fix from $1,600 2010-05-17
Kde Sc MEDIUM 5.8
CVE-2010-1000

Directory traversal vulnerability in KGet in KDE SC 4.0.0 through 4.4.3 allows remote attackers to create arbitrary files via directory traversal seq…

Mitigation only
Fix from $1,600 2010-05-17
Kde Sc MEDIUM 6.9
CVE-2010-0436

Race condition in backend/ctrl.c in KDM in KDE Software Compilation (SC) 2.2.0 through 4.4.2 allows local users to change the permissions of arbitrar…

Patch available
Fix from $1,600 2010-04-15
Kde Sc MEDIUM 6.9
CVE-2010-0923

Race condition in workspace/krunner/lock/lockdlg.cc in the KRunner lock module in kdebase in KDE SC 4.4.0 allows physically proximate attackers to by…

Patch available
Fix from $1,600 2010-03-03
Kdelibs HIGH 7.5
CVE-2009-2702

KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.50…

Mitigation only
Fix from $1,950 2009-09-08
Kmplayer HIGH 9.3
CVE-2009-2896EPSS 6%

Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code…

Fix: after 2.9.4.1433
Fix from $1,950 2009-08-20
Konqueror MEDIUM 5.0
CVE-2008-5712

The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via (1) a long COLOR attribute in an …

No fix yet
Fix from $1,600 2008-12-24
Konqueror MEDIUM 5.0
CVE-2008-4382

Konqueror in KDE 3.5.9 allows remote attackers to cause a denial of service (application crash) via Javascript that calls the alert function with a U…

Mitigation only
Fix from $1,600 2008-10-02
Kde HIGH 9.3
CVE-2008-1670

Heap-based buffer overflow in the progressive PNG Image loader (decoders/pngloader.cpp) in KHTML in KDE 4.0.x up to 4.0.3 allows remote attackers to …

Patch available
Fix from $1,950 2008-04-28
Konqueror MEDIUM 5.0
CVE-2007-6000

KDE Konqueror 3.5.6 and earlier allows remote attackers to cause a denial of service (crash) via large HTTP cookie parameters.

Fix: after 3.5.6
Fix from $1,600 2007-11-15
Kde MEDIUM 6.8
CVE-2007-4569

backend/session.c in KDM in KDE 3.3.0 through 3.5.7, when autologin is configured and "shutdown with password" is enabled, allows remote attackers to…

Patch available
Fix from $1,600 2007-09-21
Kmplayer HIGH 7.1
CVE-2007-4941

KMPlayer 2.9.3.1210 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a .avi file with certain large "indx truck…

Fix: after 2.9.3.1210
Fix from $1,950 2007-09-18
Konqueror MEDIUM 6.8
CVE-2007-4225

Visual truncation vulnerability in KDE Konqueror 3.5.7 allows remote attackers to spoof the URL address bar via an http URI with a large amount of wh…

Mitigation only
Fix from $1,600 2007-08-08
Konqueror MEDIUM 6.4
CVE-2007-3143

Visual truncation vulnerability in Konqueror 3.5.5 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a long …

No fix yet
Fix from $1,600 2007-06-11
Konqueror MEDIUM 5.0
CVE-2007-2164

Konqueror 3.5.5 release 45.4 allows remote attackers to cause a denial of service (browser crash or abort) via JavaScript that matches a regular expr…

Mitigation only
Fix from $1,600 2007-04-22
Konqueror HIGH 7.8
CVE-2007-1565

Konqueror 3.5.5 allows remote attackers to cause a denial of service (crash) by using JavaScript to read a child iframe having an ftp:// URI.

Mitigation only
Fix from $1,950 2007-03-21
Konqueror MEDIUM 6.8
CVE-2007-1564

The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to connect to other servers, perform a proxied port scan…

Mitigation only
Fix from $1,600 2007-03-21
K Mail HIGH 7.8
CVE-2007-1265

KMail 1.9.5 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents KMail from visually distinguishing between…

Mitigation only
Fix from $1,950 2007-03-06
Kdegraphics MEDIUM 5.0
CVE-2006-6297

Stack consumption vulnerability in the KFILE JPEG (kfile_jpeg) plugin in kdegraphics 3, as used by konqueror, digikam, and other KDE image browsers, …

Mitigation only
Fix from $1,600 2006-12-05
Koffice MEDIUM 6.8
CVE-2006-6120

Integer overflow in the KPresenter import filter for Microsoft PowerPoint files (filters/olefilters/lib/klaola.cc) in KOffice before 1.6.1 allows use…

Patch available
Fix from $1,600 2006-12-03
Kdebase HIGH 10.0
CVE-2006-3742

The KDE PAM configuration shipped with Fedora Core 5 causes KDM passwords to be cached, which allows attackers to login without a password by attempt…

Patch available
Fix from $1,950 2006-09-06
Arts HIGH 7.8
CVE-2006-2916

artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which al…

Patch available
Fix from $1,950 2006-06-15
Kde HIGH 7.5
CVE-2006-0019EPSS 6%

Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote…

Patch available
Fix from $1,950 2006-01-20
Konqueror MEDIUM 6.4
CVE-2005-4684

Konqueror can associate a cookie with multiple domains when the DNS resolver has a non-root domain in its search list, which allows remote attackers …

Mitigation only
Fix from $1,600 2005-12-31
Koffice HIGH 7.5
CVE-2005-2971EPSS 6%

Heap-based buffer overflow in the KWord RTF importer for KOffice 1.2.0 through 1.4.1 allows remote attackers to execute arbitrary code via a crafted …

Patch available
Fix from $1,950 2005-10-20