Kde Kdelibs vulnerabilities

8 known vulnerabilities affecting kde/kdelibs.

Total CVEs
8
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2015-7543HIGHCVSS 7.0≤ 3.5.102017-07-25
CVE-2015-7543 [HIGH] CWE-362 CVE-2015-7543: aRts 1.5.10 and kdelibs3 3.5.10 and earlier do not properly create temporary directories, which allo aRts 1.5.10 and kdelibs3 3.5.10 and earlier do not properly create temporary directories, which allows local users to hijack the IPC by pre-creating the temporary directory.
nvd
CVE-2017-8422HIGHCVSS 7.8PoC≤ 4.14.312017-05-17
CVE-2017-8422 [HIGH] CWE-290 CVE-2017-8422: KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofi KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.
nvd
CVE-2017-6410MEDIUMCVSS 5.5≤ 4.14.292017-03-02
CVE-2017-6410 [MEDIUM] CWE-319 CVE-2017-6410: kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL func kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.
nvd
CVE-2014-5033MEDIUMCVSS 6.9≤ 4.13.97v4.10.0+32 more2014-08-19
CVE-2014-5033 [MEDIUM] CVE-2014-5033: KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a po KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."
nvd
CVE-2014-3494MEDIUMCVSS 4.3v4.10.97v4.11.0+21 more2014-07-01
CVE-2014-3494 [MEDIUM] CWE-200 CVE-2014-3494: kio/usernotificationhandler.cpp in the POP3 kioslave in kdelibs 4.10.95 before 4.13.3 does not prope kio/usernotificationhandler.cpp in the POP3 kioslave in kdelibs 4.10.95 before 4.13.3 does not properly generate warning notifications, which allows man-in-the-middle attackers to obtain sensitive information via an invalid certificate.
nvd
CVE-2013-2074MEDIUMCVSS 5.0≤ 4.10.3v4.10.0+2 more2014-02-05
CVE-2013-2074 [MEDIUM] CWE-200 CVE-2013-2074: kioslave/http/http.cpp in KIO in kdelibs 4.10.3 and earlier allows attackers to discover credentials kioslave/http/http.cpp in KIO in kdelibs 4.10.3 and earlier allows attackers to discover credentials via a crafted request that triggers an "internal server error," which includes the username and password in an error message.
nvd
CVE-2009-2702HIGHCVSS 7.5v3.5.4v4.2.4+1 more2009-09-08
CVE-2009-2702 [HIGH] CWE-310 CVE-2009-2702: KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
nvd
CVE-2004-1165HIGHCVSS 7.5PoCv3.1v3.1.1+7 more2005-01-10
CVE-2004-1165 [HIGH] CVE-2004-1165: Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that con Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.
nvd