Vulnerability index

Browse CVEs

99 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kde HIGH 7.2
CVE-2005-2494

kcheckpass in KDE 3.2.0 up to 3.4.2 allows local users to gain root access via a symlink attack on lock files.

Patch available
Fix from $1,950 2005-09-06
Kde MEDIUM 5.0
CVE-2005-2101

langen2kvtml in KDE 3.0 to 3.4.2 creates insecure temporary files in /tmp with predictable names, which allows local users to overwrite arbitrary fil…

Patch available
Fix from $1,600 2005-08-17
Kde HIGH 10.0
CVE-2005-0011

Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Interface (IND…

Patch available
Fix from $1,950 2005-05-02
Kde HIGH 7.5
CVE-2005-1046EPSS 5%

Buffer overflow in the kimgio library for KDE 3.4.0 allows remote attackers to execute arbitrary code via a crafted PCX image file.

Patch available
Fix from $1,950 2005-05-02
Konqueror MEDIUM 5.0
CVE-2005-0237

The International Domain Name (IDN) support in Konqueror 3.2.1 on KDE 3.2.1 allows remote attackers to spoof domain names using punycode encoded doma…

Patch available
Fix from $1,600 2005-05-02
Kdelibs HIGH 7.5
CVE-2004-1165

Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FT…

Mitigation only
Fix from $1,950 2005-01-10
Konqueror MEDIUM 5.0
CVE-2004-0870

KDE Konqueror does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the sa…

Mitigation only
Fix from $1,600 2004-09-16
Konqueror MEDIUM 5.0
CVE-2004-0527EPSS 6%

KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that poi…

No fix yet
Fix from $1,600 2004-08-06
Konqueror HIGH 7.5
CVE-2004-0721

Konqueror 3.1.3, 3.2.2, and possibly other versions does not properly prevent a frame in one domain from injecting content into a frame that belongs …

Mitigation only
Fix from $1,950 2004-07-27
Konqueror HIGH 7.5
CVE-2004-0411EPSS 8%

The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) …

Fix: after 3.2.2
Fix from $1,950 2004-07-07
Konqueror HIGH 7.5
CVE-2003-0592

Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" …

Patch available
Fix from $1,950 2004-04-15
Kde HIGH 7.5
CVE-2003-0988EPSS 6%

Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows attackers…

Patch available
Fix from $1,950 2004-02-17
Kde HIGH 10.0
CVE-2003-0690

KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by tri…

Patch available
Fix from $1,950 2003-10-06
Kde HIGH 7.5
CVE-2003-0692

KDM in KDE 3.1.3 and earlier uses a weak session cookie generation algorithm that does not provide 128 bits of entropy, which allows attackers to gue…

Patch available
Fix from $1,950 2003-10-06
Kopete HIGH 7.5
CVE-2003-0256

The GnuPG plugin in kopete before 0.6.2 does not properly cleanse the command line when executing gpg, which allows remote attackers to execute arbit…

Mitigation only
Fix from $1,950 2003-05-27
Kde HIGH 7.5
CVE-2003-0204

KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF files, related to miss…

Patch available
Fix from $1,950 2003-05-05
Kde HIGH 7.5
CVE-2002-1393

Multiple vulnerabilities in KDE 2 and KDE 3.x through 3.0.5 do not quote certain parameters that are inserted into a shell command, which could allow…

Patch available
Fix from $1,950 2003-01-17
Kde MEDIUM 5.0
CVE-2002-2333

Buffer overflow in konqueror in KDE 2.1 through 3.0 and 3.0.2 allows remote attackers to cause a denial of service (crash) via an IMG tag with large …

Patch available
Fix from $1,600 2002-12-31
Kde HIGH 7.5
CVE-2002-1281EPSS 5%

Unknown vulnerability in the rlogin KIO subsystem (rlogin.protocol) of KDE 2.x 2.1 and later, and KDE 3.x 3.0.4 and earlier, allows local and remote …

Patch available
Fix from $1,950 2002-11-29
Kde HIGH 7.5
CVE-2002-1282

Unknown vulnerability in the telnet KIO subsystem (telnet.protocol) of KDE 2.x 2.1 and later allows local and remote attackers to execute arbitrary c…

Patch available
Fix from $1,950 2002-11-29
Kde HIGH 7.5
CVE-2002-1306EPSS 6%

Multiple buffer overflows in LISa on KDE 2.x for 2.1 and later, and KDE 3.x before 3.0.4, allow (1) local and possibly remote attackers to execute ar…

Patch available
Fix from $1,950 2002-11-29
Klisa HIGH 7.2
CVE-2002-1247

Buffer overflow in LISa allows local users to gain access to a raw socket via a long LOGNAME environment variable for the resLISa daemon.

Patch available
Fix from $1,950 2002-11-29
Kde HIGH 7.5
CVE-2002-1223

Buffer overflow in DSC 3.0 parser from GSview, as used in KGhostView in KDE 1.1 and KDE 3.0.3a, may allow attackers to cause a denial of service or e…

Patch available
Fix from $1,950 2002-10-28
Kde MEDIUM 5.0
CVE-2002-1224EPSS 9%

Directory traversal vulnerability in kpf for KDE 3.0.1 through KDE 3.0.3a allows remote attackers to read arbitrary files as the kpf user via a URL w…

Patch available
Fix from $1,600 2002-10-28
Konqueror HIGH 7.5
CVE-2002-1151

The cross-site scripting protection for Konqueror in KDE 2.2.2 and 3.0 through 3.0.3 does not properly initialize the domains on sub-frames and sub-i…

Patch available
Fix from $1,950 2002-10-11
Kde HIGH 7.5
CVE-2002-1152

Konqueror in KDE 3.0 through 3.0.2 does not properly detect the "secure" flag in an HTTP cookie, which could cause Konqueror to send the cookie acros…

Patch available
Fix from $1,950 2002-10-11
Konqueror HIGH 7.5
CVE-2002-0970

The SSL capability for Konqueror in KDE 3.0.2 and earlier does not verify the Basic Constraints for an intermediate CA-signed certificate, which allo…

Patch available
Fix from $1,950 2002-09-24
K Mail MEDIUM 5.0
CVE-2002-0342

Kmail 1.2 on KDE 2.1.1 allows remote attackers to cause a denial of service (crash) via an email message whose body is approximately 55 K long.

Patch available
Fix from $1,600 2002-06-25
Ktv HIGH 7.2
CVE-2001-0782

KDE ktvision 0.1.1-271 and earlier allows local attackers to gain root privileges via a symlink attack on a user configuration file.

Fix: after 0.1.1.271
Fix from $1,950 2001-10-18
Kvt HIGH 7.2
CVE-2000-0918

Format string vulnerability in kvt in KDE 1.1.2 may allow local users to execute arbitrary commands via a DISPLAY environmental variable that contain…

Patch available
Fix from $1,950 2000-12-19