Vulnerabilities > KDE > KDE > 3.2.1

DATE CVE VULNERABILITY TITLE RISK
2012-11-11 CVE-2012-4514 Unspecified vulnerability in KDE
rendering/render_replaced.cpp in Konqueror in KDE before 4.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted web page, related to "trying to reuse a frame with a null part."
network
low complexity
kde
5.0
2007-01-09 CVE-2007-0104 Improper Input Validation vulnerability in multiple products
The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.
network
xpdf kde CWE-20
6.8
2006-06-15 CVE-2006-2449 Symbolic Link vulnerability in KDE KDM Session Type
KDE Display Manager (KDM) in KDE 3.2.0 up to 3.5.3 allows local users to read arbitrary files via a symlink attack related to the session type for login.
local
high complexity
kde
4.0
2006-01-20 CVE-2006-0019 Remote Heap Overflow vulnerability in KDE KJS Encodeuri / Decodeuri
Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI.
network
low complexity
kde
7.5
2005-09-06 CVE-2005-2494 Local Privilege Escalation vulnerability in KDE kcheckpass
kcheckpass in KDE 3.2.0 up to 3.4.2 allows local users to gain root access via a symlink attack on lock files.
local
low complexity
kde
7.2
2005-08-17 CVE-2005-2101 Unspecified vulnerability in KDE
langen2kvtml in KDE 3.0 to 3.4.2 creates insecure temporary files in /tmp with predictable names, which allows local users to overwrite arbitrary files.
network
low complexity
kde
5.0
2005-07-26 CVE-2005-1920 Improper Preservation of Permissions vulnerability in multiple products
The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information.
network
low complexity
kde debian CWE-281
7.5
2005-05-02 CVE-2005-0237 Unspecified vulnerability in KDE and Konqueror
The International Domain Name (IDN) support in Konqueror 3.2.1 on KDE 3.2.1 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.
network
low complexity
kde
5.0
2005-04-27 CVE-2005-0206 Integer Overflow vulnerability in Xpdf PDFTOPS
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
7.5
2005-04-22 CVE-2005-0754 Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code.
network
low complexity
kde conectiva gentoo redhat ubuntu
7.5