Vulnerabilities > KDE > Kdelibs > 4.13.1

DATE CVE VULNERABILITY TITLE RISK
2017-05-17 CVE-2017-8422 Authentication Bypass by Spoofing vulnerability in KDE Kauth and Kdelibs
KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.
local
low complexity
kde CWE-290
7.2
2017-03-02 CVE-2017-6410 Cleartext Transmission of Sensitive Information vulnerability in KDE Kdelibs and KIO
kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.
network
kde CWE-319
4.3
2014-08-19 CVE-2014-5033 Race Condition vulnerability in multiple products
KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."
6.9
2014-07-01 CVE-2014-3494 Information Exposure vulnerability in multiple products
kio/usernotificationhandler.cpp in the POP3 kioslave in kdelibs 4.10.95 before 4.13.3 does not properly generate warning notifications, which allows man-in-the-middle attackers to obtain sensitive information via an invalid certificate.
network
opensuse kde CWE-200
4.3