Vulnerabilities > KDE

DATE CVE VULNERABILITY TITLE RISK
2016-12-23 CVE-2016-7967 Improper Access Control vulnerability in KDE Kmail
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled.
network
low complexity
kde CWE-284
8.1
2016-12-23 CVE-2016-7966 Code Injection vulnerability in multiple products
Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer.
network
low complexity
kde debian fedoraproject suse CWE-94
7.3
2016-12-23 CVE-2016-7787 Code Injection vulnerability in multiple products
A maliciously crafted command line for kdesu can result in the user only seeing part of the commands that will actually get executed as super user.
network
low complexity
kde opensuse CWE-94
4.9
2016-12-23 CVE-2016-2312 7PK - Security Features vulnerability in multiple products
Turning all screens off in Plasma-workspace and kscreenlocker while the lock screen is shown can result in the screen being unlocked when turning a screen on again.
6.8
2016-08-02 CVE-2016-6232 Path Traversal vulnerability in multiple products
Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads.
network
low complexity
canonical kde CWE-22
7.5
2016-07-13 CVE-2016-3100 Information Exposure vulnerability in multiple products
kinit in KDE Frameworks before 5.23.0 uses weak permissions (644) for /tmp/xauth-xxx-_y, which allows local users to obtain X11 cookies of other users and consequently capture keystrokes and possibly gain privileges by reading the file.
local
low complexity
opensuse kde CWE-200
8.4
2006-12-29 CVE-2006-6811 Reachable Assertion vulnerability in multiple products
KsIRC 1.3.12 allows remote attackers to cause a denial of service (crash) via a long PRIVMSG string when connecting to an Internet Relay Chat (IRC) server, which causes an assertion failure and results in a NULL pointer dereference.
network
low complexity
kde canonical CWE-617
6.5
2006-06-15 CVE-2006-2916 Improper Check for Dropped Privileges vulnerability in KDE Arts 1.0/1.2
artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping privileges.
local
low complexity
kde CWE-273
7.8
2005-07-26 CVE-2005-1920 Improper Preservation of Permissions vulnerability in multiple products
The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information.
network
low complexity
kde debian CWE-281
7.5
2004-09-28 CVE-2004-0689 Link Following vulnerability in multiple products
KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.
local
low complexity
kde debian CWE-59
7.1