Vulnerabilities > KDE

DATE CVE VULNERABILITY TITLE RISK
2004-04-15 CVE-2003-0592 Unspecified vulnerability in KDE Konqueror and Konqueror Embedded
Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outside the specified URL subsets, e.g.
network
low complexity
kde
7.5
2004-02-17 CVE-2003-0988 Remote Buffer Overflow vulnerability in KDE Personal Information Management Suite VCF File
Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows attackers to execute arbitrary code via a VCF file.
network
low complexity
kde
7.5
2003-12-31 CVE-2003-1478 Buffer Errors vulnerability in KDE Konqueror 3.0.3
Konqueror in KDE 3.0.3 allows remote attackers to cause a denial of service (core dump) via a web page that begins with a "xFFxFE" byte sequence and a large number of CRLF sequences, as demonstrated using freeze.htm.
network
kde CWE-119
4.3
2003-10-06 CVE-2003-0692 Unspecified vulnerability in KDE
KDM in KDE 3.1.3 and earlier uses a weak session cookie generation algorithm that does not provide 128 bits of entropy, which allows attackers to guess session cookies via brute force methods and gain access to the user session.
network
low complexity
kde
7.5
2003-10-06 CVE-2003-0690 Unspecified vulnerability in KDE
KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5 module.
network
low complexity
kde
critical
10.0
2003-08-27 CVE-2003-0459 KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.
network
low complexity
kde redhat
5.0
2003-06-16 CVE-2003-0370 Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.
network
low complexity
apple kde redhat turbolinux
7.5
2003-06-09 CVE-2003-0355 Remote Security vulnerability in Konqueror Embedded
Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates.
network
low complexity
apple kde
5.0
2003-05-27 CVE-2003-0256 Unspecified vulnerability in KDE Kopete 0.6.1
The GnuPG plugin in kopete before 0.6.2 does not properly cleanse the command line when executing gpg, which allows remote attackers to execute arbitrary commands.
network
low complexity
kde
7.5
2003-05-05 CVE-2003-0204 Unspecified vulnerability in KDE
KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF files, related to missing -dPARANOIDSAFER and -dSAFER arguments when using the kghostview Ghostscript viewer.
network
low complexity
kde
7.5