Vulnerabilities > KDE > Konqueror > High

DATE CVE VULNERABILITY TITLE RISK
2007-03-21 CVE-2007-1565 Denial-Of-Service vulnerability in KDE Konqueror 3.5.5
Konqueror 3.5.5 allows remote attackers to cause a denial of service (crash) by using JavaScript to read a child iframe having an ftp:// URI.
network
low complexity
kde
7.8
2005-01-10 CVE-2004-1165 Unspecified vulnerability in KDE Kdelibs and Konqueror
Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.
network
low complexity
kde
7.5
2005-01-10 CVE-2004-1158 Remote Window Hijacking vulnerability in KDE Konqueror
Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window or tab whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.
network
low complexity
kde mandrakesoft redhat
7.5
2004-12-23 CVE-2004-0867 Permissions, Privileges, and Access Controls vulnerability in multiple products
Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.
network
low complexity
kde microsoft mozilla suse CWE-264
7.5
2004-10-20 CVE-2004-0746 Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.
network
low complexity
kde gentoo mandrakesoft suse
7.5
2004-09-16 CVE-2004-0866 Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.
network
low complexity
kde mozilla microsoft suse
7.5
2004-07-27 CVE-2004-0721 Unspecified vulnerability in KDE Konqueror 3.1.3/3.2.2
Konqueror 3.1.3, 3.2.2, and possibly other versions does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.
network
low complexity
kde
7.5
2004-04-15 CVE-2003-0592 Unspecified vulnerability in KDE Konqueror and Konqueror Embedded
Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outside the specified URL subsets, e.g.
network
low complexity
kde
7.5
2002-10-11 CVE-2002-1151 Unspecified vulnerability in KDE and Konqueror
The cross-site scripting protection for Konqueror in KDE 2.2.2 and 3.0 through 3.0.3 does not properly initialize the domains on sub-frames and sub-iframes, which can allow remote attackers to execute script and steal cookies from subframes that are in other domains.
network
low complexity
kde
7.5
2002-09-24 CVE-2002-0970 Unspecified vulnerability in KDE and Konqueror
The SSL capability for Konqueror in KDE 3.0.2 and earlier does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack.
network
low complexity
kde
7.5