Vulnerabilities > KDE
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2010-08-30 | CVE-2010-2575 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in KDE SC Heap-based buffer overflow in the RLE decompression functionality in the TranscribePalmImageToJPEG function in generators/plucker/inplug/image.cpp in Okular in KDE SC 4.3.0 through 4.5.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image in a PDB file. | 6.8 |
2010-08-02 | CVE-2009-4976 | Cross-Site Scripting vulnerability in URS Wolfer Kwebkitpart 0.9.6 Cross-site scripting (XSS) vulnerability in webkitpart.cpp in kwebkitpart allows remote attackers to inject arbitrary web script or HTML via a URL associated with a nonexistent domain name, related to a "universal XSS" issue, a similar vulnerability to CVE-2010-2536. | 4.3 |
2010-05-17 | CVE-2010-1511 | Permissions, Privileges, and Access Controls vulnerability in KDE SC and Kget KGet 2.4.2 in KDE SC 4.0.0 through 4.4.3 does not properly request download confirmation from the user, which makes it easier for remote attackers to overwrite arbitrary files via a crafted metalink file. | 6.4 |
2010-05-17 | CVE-2010-1000 | Path Traversal vulnerability in KDE SC Directory traversal vulnerability in KGet in KDE SC 4.0.0 through 4.4.3 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file. | 5.8 |
2010-04-15 | CVE-2010-0436 | Race Condition vulnerability in KDE SC Race condition in backend/ctrl.c in KDM in KDE Software Compilation (SC) 2.2.0 through 4.4.2 allows local users to change the permissions of arbitrary files, and consequently gain privileges, by blocking the removal of a certain directory that contains a control socket, related to improper interaction with ksm. | 6.9 |
2010-03-03 | CVE-2010-0923 | Race Condition vulnerability in KDE SC 4.4.0 Race condition in workspace/krunner/lock/lockdlg.cc in the KRunner lock module in kdebase in KDE SC 4.4.0 allows physically proximate attackers to bypass KScreenSaver screen locking and access an unattended workstation by pressing the Enter key at a certain time, related to multiple forked processes. | 6.9 |
2009-12-21 | CVE-2009-4035 | Code Injection vulnerability in multiple products The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to execute arbitrary code via a PDF file with a crafted Type 1 font that can produce a negative value, leading to a signed-to-unsigned integer conversion error and a buffer overflow. | 9.3 |
2009-09-08 | CVE-2009-2702 | Cryptographic Issues vulnerability in KDE Kdelibs 3.5.4/4.2.4/4.3 KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. | 7.5 |
2009-08-20 | CVE-2009-2896 | Buffer Errors vulnerability in KDE Kmplayer 2.9.3.1210 Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a subtitle (.srt) playlist file. | 9.3 |
2009-07-20 | CVE-2009-2537 | Resource Management Errors vulnerability in KDE Konqueror KDE Konqueror allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692. | 4.3 |