Vulnerability index

Browse CVEs

30 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Kmail MEDIUM 5.3
CVE-2021-38373

In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" …

Mitigation only
Fix from $1,600 2021-08-10
Amarok MEDIUM 5.5
CVE-2020-13152

A remote user can create a specially crafted M3U file, media playlist file that when loaded by the target user, will trigger a memory leak, whereby A…

No fix yet
Fix from $1,600 2020-05-20
Paste Applet MEDIUM 5.5
CVE-2013-2213

The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addons uses the GNU C Library rand function's linear congruential generato…

No fix yet
Fix from $1,600 2020-02-11
Kde MEDIUM 6.8
CVE-2012-4515EPSS 6%

Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, allows remote attacker…

No fix yet
Fix from $1,600 2012-11-11
Kde MEDIUM 6.4
CVE-2012-4513EPSS 13%

khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via l…

No fix yet
Fix from $1,600 2012-11-11
Kcheckpass MEDIUM 6.9
CVE-2011-5054

kcheckpass passes a user-supplied argument to the pam_start function, often within a setuid environment, which allows local users to invoke any confi…

Mitigation only
Fix from $1,600 2012-01-06
Kget MEDIUM 6.4
CVE-2010-1511

KGet 2.4.2 in KDE SC 4.0.0 through 4.4.3 does not properly request download confirmation from the user, which makes it easier for remote attackers to…

Mitigation only
Fix from $1,600 2010-05-17
Kde Sc MEDIUM 5.8
CVE-2010-1000

Directory traversal vulnerability in KGet in KDE SC 4.0.0 through 4.4.3 allows remote attackers to create arbitrary files via directory traversal seq…

Mitigation only
Fix from $1,600 2010-05-17
Kdelibs HIGH 7.5
CVE-2009-2702

KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.50…

Mitigation only
Fix from $1,950 2009-09-08
Konqueror MEDIUM 5.0
CVE-2008-5712

The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via (1) a long COLOR attribute in an …

No fix yet
Fix from $1,600 2008-12-24
Konqueror MEDIUM 5.0
CVE-2008-4382

Konqueror in KDE 3.5.9 allows remote attackers to cause a denial of service (application crash) via Javascript that calls the alert function with a U…

Mitigation only
Fix from $1,600 2008-10-02
Konqueror MEDIUM 6.8
CVE-2007-4225

Visual truncation vulnerability in KDE Konqueror 3.5.7 allows remote attackers to spoof the URL address bar via an http URI with a large amount of wh…

Mitigation only
Fix from $1,600 2007-08-08
Konqueror MEDIUM 6.4
CVE-2007-3143

Visual truncation vulnerability in Konqueror 3.5.5 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a long …

No fix yet
Fix from $1,600 2007-06-11
Konqueror MEDIUM 5.0
CVE-2007-2164

Konqueror 3.5.5 release 45.4 allows remote attackers to cause a denial of service (browser crash or abort) via JavaScript that matches a regular expr…

Mitigation only
Fix from $1,600 2007-04-22
Konqueror HIGH 7.8
CVE-2007-1565

Konqueror 3.5.5 allows remote attackers to cause a denial of service (crash) by using JavaScript to read a child iframe having an ftp:// URI.

Mitigation only
Fix from $1,950 2007-03-21
Konqueror MEDIUM 6.8
CVE-2007-1564

The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to connect to other servers, perform a proxied port scan…

Mitigation only
Fix from $1,600 2007-03-21
K Mail HIGH 7.8
CVE-2007-1265

KMail 1.9.5 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents KMail from visually distinguishing between…

Mitigation only
Fix from $1,950 2007-03-06
Kdegraphics MEDIUM 5.0
CVE-2006-6297

Stack consumption vulnerability in the KFILE JPEG (kfile_jpeg) plugin in kdegraphics 3, as used by konqueror, digikam, and other KDE image browsers, …

Mitigation only
Fix from $1,600 2006-12-05
Konqueror MEDIUM 6.4
CVE-2005-4684

Konqueror can associate a cookie with multiple domains when the DNS resolver has a non-root domain in its search list, which allows remote attackers …

Mitigation only
Fix from $1,600 2005-12-31
Kdelibs HIGH 7.5
CVE-2004-1165

Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FT…

Mitigation only
Fix from $1,950 2005-01-10
Konqueror MEDIUM 5.0
CVE-2004-0870

KDE Konqueror does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the sa…

Mitigation only
Fix from $1,600 2004-09-16
Konqueror MEDIUM 5.0
CVE-2004-0527EPSS 6%

KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that poi…

No fix yet
Fix from $1,600 2004-08-06
Konqueror HIGH 7.5
CVE-2004-0721

Konqueror 3.1.3, 3.2.2, and possibly other versions does not properly prevent a frame in one domain from injecting content into a frame that belongs …

Mitigation only
Fix from $1,950 2004-07-27
Kopete HIGH 7.5
CVE-2003-0256

The GnuPG plugin in kopete before 0.6.2 does not properly cleanse the command line when executing gpg, which allows remote attackers to execute arbit…

Mitigation only
Fix from $1,950 2003-05-27
Kde HIGH 7.2
CVE-2000-0460

Buffer overflow in KDE kdesud on Linux allows local uses to gain privileges via a long DISPLAY environmental variable.

No fix yet
Fix from $1,950 2000-05-27
Kde HIGH 7.2
CVE-2000-0393

The KDE kscd program does not drop privileges when executing a program specified in a user's SHELL environmental variable, which allows the user to g…

Mitigation only
Fix from $1,950 2000-05-16
Kde HIGH 7.2
CVE-1999-1107

Buffer overflow in kppp in KDE allows local users to gain root access via a long PATH environmental variable.

Mitigation only
Fix from $1,950 1998-11-18
Kde HIGH 7.2
CVE-1999-1096

Buffer overflow in kscreensaver in KDE klock allows local users to gain root privileges via a long HOME environmental variable.

Mitigation only
Fix from $1,950 1998-05-16
Kde HIGH 7.2
CVE-1999-1106

Buffer overflow in kppp in KDE allows local users to gain root access via a long -c (account_name) command line argument.

No fix yet
Fix from $1,950 1998-04-29
Kde MEDIUM 5.0
CVE-1999-1267

KDE file manager (kfm) uses a TCP server for certain file operations, which allows remote attackers to modify arbitrary files by sending a copy comma…

Mitigation only
Fix from $1,600 1997-05-05