Vulnerabilities > KDE

DATE CVE VULNERABILITY TITLE RISK
2014-02-04 CVE-2011-2725 Path Traversal vulnerability in multiple products
Directory traversal vulnerability in Ark 4.7.x and earlier allows remote attackers to delete and force the display of arbitrary files via ..
6.8
2013-09-16 CVE-2013-4132 Cryptographic Issues vulnerability in multiple products
KDE-Workspace 4.10.5 and earlier does not properly handle the return value of the glibc 2.17 crypt and pw_encrypt functions, which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via (1) an invalid salt or a (2) DES or (3) MD5 encrypted password, when FIPS-140 is enable, to KDM or an (4) invalid password to KCheckPass.
network
low complexity
kde opensuse CWE-310
5.0
2012-11-11 CVE-2012-4515 Resource Management Errors vulnerability in KDE 4.7.3
Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by accessing an iframe when it is being updated.
network
kde CWE-399
6.8
2012-11-11 CVE-2012-4514 Unspecified vulnerability in KDE
rendering/render_replaced.cpp in Konqueror in KDE before 4.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted web page, related to "trying to reuse a frame with a null part."
network
low complexity
kde
5.0
2012-11-11 CVE-2012-4513 Buffer Errors vulnerability in KDE 4.7.3
khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via large canvas dimensions, which leads to an unexpected sign extension and a heap-based buffer over-read.
network
low complexity
kde CWE-119
6.4
2012-08-07 CVE-2012-3413 Configuration vulnerability in KDE PIM 4.6/4.8
The HTMLQuoteColorer::process function in messageviewer/htmlquotecolorer.cpp in KDE PIM 4.6 through 4.8 does not disable JavaScript, Java, and Plugins, which allows remote attackers to inject arbitrary web script or HTML via a crafted email.
network
kde CWE-16
4.3
2012-01-06 CVE-2011-5054 Improper Authentication vulnerability in KDE Kcheckpass
kcheckpass passes a user-supplied argument to the pam_start function, often within a setuid environment, which allows local users to invoke any configured PAM stack, and possibly trigger unintended side effects, via an arbitrary valid PAM service name, a different vulnerability than CVE-2011-4122.
local
kde CWE-287
6.9
2010-11-05 CVE-2010-3704 Improper Input Validation vulnerability in multiple products
The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PDF file with a crafted PostScript Type1 font that contains a negative array index, which bypasses input validation and triggers memory corruption.
6.8
2010-08-30 CVE-2010-2575 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in KDE SC
Heap-based buffer overflow in the RLE decompression functionality in the TranscribePalmImageToJPEG function in generators/plucker/inplug/image.cpp in Okular in KDE SC 4.3.0 through 4.5.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image in a PDB file.
network
kde CWE-119
6.8
2010-08-02 CVE-2009-4976 Cross-Site Scripting vulnerability in URS Wolfer Kwebkitpart 0.9.6
Cross-site scripting (XSS) vulnerability in webkitpart.cpp in kwebkitpart allows remote attackers to inject arbitrary web script or HTML via a URL associated with a nonexistent domain name, related to a "universal XSS" issue, a similar vulnerability to CVE-2010-2536.
4.3