Kde Konqueror vulnerabilities
32 known vulnerabilities affecting kde/konqueror.
Total CVEs
32
CISA KEV
0
Public exploits
10
Exploited in wild
0
Severity breakdown
HIGH12MEDIUM17LOW3
Vulnerabilities
Page 1 of 2
CVE-2012-4512P3HIGHCVSS 8.8PoCv4.7.32020-02-08
CVE-2012-4512 [HIGH] CWE-843 CVE-2012-4512: The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."
nvd
CVE-2004-1165P3HIGHCVSS 7.5PoCv3.3.12005-01-10
CVE-2004-1165 [HIGH] CVE-2004-1165: Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that con
Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.
nvd
CVE-2007-1564P4MEDIUMCVSS 6.8PoCv3.5.52007-03-21
CVE-2007-1564 [MEDIUM] CWE-200 CVE-2007-1564: The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to conn
The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.
nvd
CVE-2004-0527P4MEDIUMCVSS 5.0PoCv2.1.1v2.2.2+10 more2004-08-06
CVE-2004-0527 [MEDIUM] CVE-2004-0527: KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar vi
KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.
nvd
CVE-2007-6000P4MEDIUMCVSS 5.0PoC≤ 3.5.62007-11-15
CVE-2007-6000 [MEDIUM] CWE-399 CVE-2007-6000: KDE Konqueror 3.5.6 and earlier allows remote attackers to cause a denial of service (crash) via lar
KDE Konqueror 3.5.6 and earlier allows remote attackers to cause a denial of service (crash) via large HTTP cookie parameters.
nvd
CVE-2007-1308P4MEDIUMCVSS 4.3PoCv3.5.52007-03-07
CVE-2007-1308 [MEDIUM] CWE-399 CVE-2007-1308: ecma/kjs_html.cpp in KDE JavaScript (KJS), as used in Konqueror in KDE 3.5.5, allows remote attacker
ecma/kjs_html.cpp in KDE JavaScript (KJS), as used in Konqueror in KDE 3.5.5, allows remote attackers to cause a denial of service (crash) by accessing the content of an iframe with an ftp:// URI in the src attribute, probably due to a NULL pointer dereference.
nvd
CVE-2008-5712P4MEDIUMCVSS 5.0PoCv3.5.92008-12-24
CVE-2008-5712 [MEDIUM] CVE-2008-5712: The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (applica
The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via (1) a long COLOR attribute in an HR element; or a long (a) BGCOLOR or (b) BORDERCOLOR attribute in a (2) TABLE, (3) TD, or (4) TR element. NOTE: the FONT vector is already covered by CVE-2008-4514.
nvd
CVE-2004-0411P3HIGHCVSS 7.5≤ 3.2.22004-07-07
CVE-2004-0411 [HIGH] CWE-88 CVE-2004-0411: The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that b
The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attackers to manipulate the options that are passed to the associated programs, possibly to read arbitrary files or execute arbitrary code.
nvd
CVE-2003-1478P4MEDIUMCVSS 4.3PoCv3.0.32003-12-31
CVE-2003-1478 [MEDIUM] CWE-119 CVE-2003-1478: Konqueror in KDE 3.0.3 allows remote attackers to cause a denial of service (core dump) via a web pa
Konqueror in KDE 3.0.3 allows remote attackers to cause a denial of service (core dump) via a web page that begins with a "xFFxFE" byte sequence and a large number of CRLF sequences, as demonstrated using freeze.htm.
nvd
CVE-2004-0867P4HIGHCVSS 7.5v2.1.1v2.1.2+16 more2004-12-23
CVE-2004-0867 [HIGH] CWE-264 CVE-2004-0867: Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such a
Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session. NOTE: it was later reported that 2.x is also affected.
nvd
CVE-2007-4229P4MEDIUMCVSS 4.3PoC≤ 3.5.72007-08-08
CVE-2007-4229 [MEDIUM] CVE-2007-4229: Unspecified vulnerability in KDE Konqueror 3.5.7 and earlier allows remote attackers to cause a deni
Unspecified vulnerability in KDE Konqueror 3.5.7 and earlier allows remote attackers to cause a denial of service (failed assertion and application crash) via certain malformed HTML, as demonstrated by a document containing TEXTAREA, BUTTON, BR, BDO, PRE, FRAMESET, and A tags. NOTE: the provenance of this information is unknown; the details are obtained solel
nvd
CVE-2006-3672P4LOWCVSS 2.6PoC≤ 3.5.1v2.1.1+22 more2006-07-18
CVE-2006-3672 [LOW] CVE-2006-3672: KDE Konqueror 3.5.1 and earlier allows remote attackers to cause a denial of service (application cr
KDE Konqueror 3.5.1 and earlier allows remote attackers to cause a denial of service (application crash) by calling the replaceChild method on a DOM object, which triggers a null dereference, as demonstrated by calling document.replaceChild with a 0 (zero) argument.
nvd
CVE-2003-0592P4HIGHCVSS 7.5v2.1.1v2.2.2+8 more2004-04-15
CVE-2003-0592 [HIGH] CVE-2003-0592: Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie acces
Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target app
nvd
CVE-2007-4225P4MEDIUMCVSS 6.8v3.5.72007-08-08
CVE-2007-4225 [MEDIUM] CVE-2007-4225: Visual truncation vulnerability in KDE Konqueror 3.5.7 allows remote attackers to spoof the URL addr
Visual truncation vulnerability in KDE Konqueror 3.5.7 allows remote attackers to spoof the URL address bar via an http URI with a large amount of whitespace in the user/password portion.
nvd
CVE-2007-3143P4MEDIUMCVSS 6.4v3.5.52007-06-11
CVE-2007-3143 [MEDIUM] CVE-2007-3143: Visual truncation vulnerability in Konqueror 3.5.5 allows remote attackers to spoof the address bar
Visual truncation vulnerability in Konqueror 3.5.5 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a long hostname, which is truncated after a certain number of characters, as demonstrated by a phishing attack using HTTP Basic Authentication.
nvd
CVE-2004-0866P4HIGHCVSS 7.5v2.1.1v2.1.2+16 more2004-09-16
CVE-2004-0866 [HIGH] CVE-2004-0866: Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such a
Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.
nvd
CVE-2004-1158P4HIGHCVSS 7.5v2.1.1v2.1.2+20 more2005-01-10
CVE-2004-1158 [HIGH] CVE-2004-1158: Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary
Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window or tab whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.
nvd
CVE-2002-0970P4HIGHCVSS 7.5v2.2.2v3.0+2 more2002-09-24
CVE-2002-0970 [HIGH] CVE-2002-0970: The SSL capability for Konqueror in KDE 3.0.2 and earlier does not verify the Basic Constraints for
The SSL capability for Konqueror in KDE 3.0.2 and earlier does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack.
nvd
CVE-2007-1565P4HIGHCVSS 7.8v3.5.52007-03-21
CVE-2007-1565 [HIGH] CVE-2007-1565: Konqueror 3.5.5 allows remote attackers to cause a denial of service (crash) by using JavaScript to
Konqueror 3.5.5 allows remote attackers to cause a denial of service (crash) by using JavaScript to read a child iframe having an ftp:// URI.
nvd
CVE-2004-0746P4HIGHCVSS 7.5v3.0v3.0.1+11 more2004-10-20
CVE-2004-0746 [HIGH] CVE-2004-0746: Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level do
Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.
nvd
1 / 2Next →