Vulnerabilities > KDE

DATE CVE VULNERABILITY TITLE RISK
2010-05-17 CVE-2010-1511 Permissions, Privileges, and Access Controls vulnerability in KDE SC and Kget
KGet 2.4.2 in KDE SC 4.0.0 through 4.4.3 does not properly request download confirmation from the user, which makes it easier for remote attackers to overwrite arbitrary files via a crafted metalink file.
network
low complexity
kde CWE-264
6.4
2010-05-17 CVE-2010-1000 Path Traversal vulnerability in KDE SC
Directory traversal vulnerability in KGet in KDE SC 4.0.0 through 4.4.3 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.
network
kde CWE-22
5.8
2010-04-15 CVE-2010-0436 Race Condition vulnerability in KDE SC
Race condition in backend/ctrl.c in KDM in KDE Software Compilation (SC) 2.2.0 through 4.4.2 allows local users to change the permissions of arbitrary files, and consequently gain privileges, by blocking the removal of a certain directory that contains a control socket, related to improper interaction with ksm.
local
kde CWE-362
6.9
2010-03-03 CVE-2010-0923 Race Condition vulnerability in KDE SC 4.4.0
Race condition in workspace/krunner/lock/lockdlg.cc in the KRunner lock module in kdebase in KDE SC 4.4.0 allows physically proximate attackers to bypass KScreenSaver screen locking and access an unattended workstation by pressing the Enter key at a certain time, related to multiple forked processes.
local
kde CWE-362
6.9
2009-12-21 CVE-2009-4035 Code Injection vulnerability in multiple products
The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to execute arbitrary code via a PDF file with a crafted Type 1 font that can produce a negative value, leading to a signed-to-unsigned integer conversion error and a buffer overflow.
network
gnome kde xpdf CWE-94
critical
9.3
2009-09-08 CVE-2009-2702 Cryptographic Issues vulnerability in KDE Kdelibs 3.5.4/4.2.4/4.3
KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
network
low complexity
kde CWE-310
7.5
2009-08-20 CVE-2009-2896 Buffer Errors vulnerability in KDE Kmplayer 2.9.3.1210
Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a subtitle (.srt) playlist file.
network
kde CWE-119
critical
9.3
2009-07-20 CVE-2009-2537 Resource Management Errors vulnerability in KDE Konqueror
KDE Konqueror allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.
network
kde CWE-399
4.3
2008-12-24 CVE-2008-5712 Improper Input Validation vulnerability in KDE Konqueror 3.5.9
The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via (1) a long COLOR attribute in an HR element; or a long (a) BGCOLOR or (b) BORDERCOLOR attribute in a (2) TABLE, (3) TD, or (4) TR element.
network
low complexity
kde CWE-20
5.0
2008-12-22 CVE-2008-5698 Resource Management Errors vulnerability in KDE Konqueror
HTMLTokenizer::scriptHandler in Konqueror in KDE 3.5.9 and 3.5.10 allows remote attackers to cause a denial of service (application crash) via an invalid document.load call that triggers use of a deleted object.
network
kde CWE-399
4.3