Kde vulnerabilities
62 known vulnerabilities affecting kde/kde.
Total CVEs
62
CISA KEV
0
Public exploits
12
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH30MEDIUM22LOW4
Vulnerabilities
Page 1 of 4
CVE-2012-4512HIGHCVSS 8.8PoCv4.7.32020-02-08
CVE-2012-4512 [HIGH] CWE-843 CVE-2012-4512: The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."
nvd
CVE-2012-4515MEDIUMCVSS 6.8PoCv4.7.32012-11-11
CVE-2012-4515 [MEDIUM] CWE-399 CVE-2012-4515: Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when
Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by accessing an iframe when it is being updated.
nvd
CVE-2012-4513MEDIUMCVSS 6.4PoCv4.7.32012-11-11
CVE-2012-4513 [MEDIUM] CWE-119 CVE-2012-4513: khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial
khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via large canvas dimensions, which leads to an unexpected sign extension and a heap-based buffer over-read.
nvd
CVE-2012-4514MEDIUMCVSS 5.0PoC≤ 4.9.2v1.0+75 more2012-11-11
CVE-2012-4514 [MEDIUM] CVE-2012-4514: rendering/render_replaced.cpp in Konqueror in KDE before 4.9.3 allows remote attackers to cause a de
rendering/render_replaced.cpp in Konqueror in KDE before 4.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted web page, related to "trying to reuse a frame with a null part."
nvd
CVE-2008-1670CRITICALCVSS 9.3v4.0.0v4.0.1+2 more2008-04-28
CVE-2008-1670 [CRITICAL] CWE-119 CVE-2008-1670: Heap-based buffer overflow in the progressive PNG Image loader (decoders/pngloader.cpp) in KHTML in
Heap-based buffer overflow in the progressive PNG Image loader (decoders/pngloader.cpp) in KHTML in KDE 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted image.
nvd
CVE-2008-1671MEDIUMCVSS 4.6v3.5.5v3.5.6+3 more2008-04-28
CVE-2008-1671 [MEDIUM] CWE-16 CVE-2008-1671: start_kdeinit in KDE 3.5.5 through 3.5.9, when installed setuid root, allows local users to cause a
start_kdeinit in KDE 3.5.5 through 3.5.9, when installed setuid root, allows local users to cause a denial of service and possibly execute arbitrary code via "user-influenceable input" (probably command-line arguments) that cause start_kdeinit to send SIGUSR1 signals to other processes.
nvd
CVE-2007-4569MEDIUMCVSS 6.8v3.3v3.3.0+16 more2007-09-21
CVE-2007-4569 [MEDIUM] CWE-264 CVE-2007-4569: backend/session.c in KDM in KDE 3.3.0 through 3.5.7, when autologin is configured and "shutdown with
backend/session.c in KDM in KDE 3.3.0 through 3.5.7, when autologin is configured and "shutdown with password" is enabled, allows remote attackers to bypass the password requirement and login to arbitrary accounts via unspecified vectors.
nvd
CVE-2007-0104MEDIUMCVSS 6.8v3.2v3.2.1+10 more2007-01-09
CVE-2007-0104 [MEDIUM] CWE-20 CVE-2007-0104: The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.
The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictiona
nvd
CVE-2006-2933MEDIUMCVSS 4.6v3.1.2v3.1.32006-07-27
CVE-2006-2933 [MEDIUM] CVE-2006-2933: kdesktop_lock in kdebase before 3.1.3-5.11 for KDE in Red Hat Enterprise Linux (RHEL) 3 does not pro
kdesktop_lock in kdebase before 3.1.3-5.11 for KDE in Red Hat Enterprise Linux (RHEL) 3 does not properly terminate, which can prevent the screensaver from activating or prevent users from manually locking the desktop.
nvd
CVE-2006-2449MEDIUMCVSS 4.0v3.2v3.2.1+12 more2006-06-15
CVE-2006-2449 [MEDIUM] CVE-2006-2449: KDE Display Manager (KDM) in KDE 3.2.0 up to 3.5.3 allows local users to read arbitrary files via a
KDE Display Manager (KDM) in KDE 3.2.0 up to 3.5.3 allows local users to read arbitrary files via a symlink attack related to the session type for login.
nvd
CVE-2006-0019HIGHCVSS 7.5v3.2v3.2.0+15 more2006-01-20
CVE-2006-0019 [HIGH] CVE-2006-0019: Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interprete
Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI.
nvd
CVE-2005-2494HIGHCVSS 7.2v3.2.0v3.2.1+8 more2005-09-06
CVE-2005-2494 [HIGH] CVE-2005-2494: kcheckpass in KDE 3.2.0 up to 3.4.2 allows local users to gain root access via a symlink attack on l
kcheckpass in KDE 3.2.0 up to 3.4.2 allows local users to gain root access via a symlink attack on lock files.
nvd
CVE-2005-2101MEDIUMCVSS 5.0v3.0v3.0.1+25 more2005-08-17
CVE-2005-2101 [MEDIUM] CVE-2005-2101: langen2kvtml in KDE 3.0 to 3.4.2 creates insecure temporary files in /tmp with predictable names, wh
langen2kvtml in KDE 3.0 to 3.4.2 creates insecure temporary files in /tmp with predictable names, which allows local users to overwrite arbitrary files.
nvd
CVE-2005-1920HIGHCVSS 7.5≥ 3.2, ≤ 3.4.02005-07-26
CVE-2005-1920 [HIGH] CWE-281 CVE-2005-1920: The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same
The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information.
nvd
CVE-2005-1852HIGHCVSS 7.5v3.2.3v3.3+5 more2005-07-26
CVE-2005-1852 [HIGH] CWE-189 CVE-2005-1852: Multiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, G
Multiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, GNU Gadu, CenterICQ, Kadu, and other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an incoming message.
nvd
CVE-2005-0011CRITICALCVSS 10.0v3.3v3.3.1+1 more2005-05-02
CVE-2005-0011 [CRITICAL] CVE-2005-0011: Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support
Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Interface (INDI) in KDE 3.3 to 3.3.2, allow local users and remote attackers to execute arbitrary code via stack-based buffer overflows.
nvd
CVE-2005-1046HIGHCVSS 7.5v3.4.02005-05-02
CVE-2005-1046 [HIGH] CVE-2005-1046: Buffer overflow in the kimgio library for KDE 3.4.0 allows remote attackers to execute arbitrary cod
Buffer overflow in the kimgio library for KDE 3.4.0 allows remote attackers to execute arbitrary code via a crafted PCX image file.
nvd
CVE-2005-0404MEDIUMCVSS 5.0PoCv3.3.22005-05-02
CVE-2005-0404 [MEDIUM] CVE-2005-0404: KMail 1.7.1 in KDE 3.3.2 allows remote attackers to spoof email information, such as whether the ema
KMail 1.7.1 in KDE 3.3.2 allows remote attackers to spoof email information, such as whether the email has been digitally signed or encrypted, via HTML formatted email.
nvd
CVE-2005-0205MEDIUMCVSS 4.6v3.1v3.1.1+4 more2005-05-02
CVE-2005-0205 [MEDIUM] CVE-2005-0205: KPPP 2.1.2 in KDE 3.1.5 and earlier, when setuid root without certain wrappers, does not properly cl
KPPP 2.1.2 in KDE 3.1.5 and earlier, when setuid root without certain wrappers, does not properly close a privileged file descriptor for a domain socket, which allows local users to read and write to /etc/hosts and /etc/resolv.conf and gain control over DNS name resolution by opening a number of file descriptors before executing kppp.
nvd
CVE-2005-0237MEDIUMCVSS 5.0v3.2.12005-05-02
CVE-2005-0237 [MEDIUM] CVE-2005-0237: The International Domain Name (IDN) support in Konqueror 3.2.1 on KDE 3.2.1 allows remote attackers
The International Domain Name (IDN) support in Konqueror 3.2.1 on KDE 3.2.1 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.
nvd
1 / 4Next →