CVE-2004-1145

6 documents5 sources
Severity
5.0MEDIUM
EPSS
4.5%
top 10.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 15
Latest updateApr 29

Description

Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows remote attackers to bypass sandbox restrictions and read or write arbitrary files.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages7 packages

NVDsgi/propack3.0
NVDconectiva/linux10.0, 9.0+1
NVDsuse/suse_linux6 versions+5
NVDethereal_group/ethereal25 versions+24

Also affects: Debian Linux 3.0, Enterprise Linux 2.1, 3.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-95hh-399q-cvw3: Multiple vulnerabilities in Konqueror in KDE 32022-04-29
CVEList
CVE-2004-1145: Multiple vulnerabilities in Konqueror in KDE 32004-12-31

📋Vendor Advisories

1
Red Hat
security flaw2004-12-20

💬Community

1
Bugzilla
CVE-2004-1145 security flaw2018-08-16