Kde Konqueror vulnerabilities
32 known vulnerabilities affecting kde/konqueror.
Total CVEs
32
CISA KEV
0
Public exploits
10
Exploited in wild
0
Severity breakdown
HIGH12MEDIUM17LOW3
Vulnerabilities
Page 2 of 2
CVE-2004-0867HIGHCVSS 7.5v2.1.1v2.1.2+16 more2004-12-23
CVE-2004-0867 [HIGH] CWE-264 CVE-2004-0867: Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such a
Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session. NOTE: it was later reported that 2.x is also affected.
nvd
CVE-2004-0746HIGHCVSS 7.5v3.0v3.0.1+11 more2004-10-20
CVE-2004-0746 [HIGH] CVE-2004-0746: Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level do
Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.
nvd
CVE-2004-0866HIGHCVSS 7.5v2.1.1v2.1.2+16 more2004-09-16
CVE-2004-0866 [HIGH] CVE-2004-0866: Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such a
Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.
nvd
CVE-2004-0870MEDIUMCVSS 5.0v2.1.1v2.1.2+16 more2004-09-16
CVE-2004-0870 [MEDIUM] CVE-2004-0870: KDE Konqueror does not prevent cookies that are sent over an insecure channel (HTTP) from also being
KDE Konqueror does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie Injection."
nvd
CVE-2004-0527MEDIUMCVSS 5.0PoCv2.1.1v2.2.2+10 more2004-08-06
CVE-2004-0527 [MEDIUM] CVE-2004-0527: KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar vi
KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.
nvd
CVE-2004-0721HIGHCVSS 7.5v3.1.3v3.2.22004-07-27
CVE-2004-0721 [HIGH] CVE-2004-0721: Konqueror 3.1.3, 3.2.2, and possibly other versions does not properly prevent a frame in one domain
Konqueror 3.1.3, 3.2.2, and possibly other versions does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.
nvd
CVE-2004-0411HIGHCVSS 7.5≤ 3.2.22004-07-07
CVE-2004-0411 [HIGH] CWE-88 CVE-2004-0411: The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that b
The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attackers to manipulate the options that are passed to the associated programs, possibly to read arbitrary files or execute arbitrary code.
nvd
CVE-2003-0592HIGHCVSS 7.5v2.1.1v2.2.2+8 more2004-04-15
CVE-2003-0592 [HIGH] CVE-2003-0592: Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie acces
Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target app
nvd
CVE-2003-1478MEDIUMCVSS 4.3PoCv3.0.32003-12-31
CVE-2003-1478 [MEDIUM] CWE-119 CVE-2003-1478: Konqueror in KDE 3.0.3 allows remote attackers to cause a denial of service (core dump) via a web pa
Konqueror in KDE 3.0.3 allows remote attackers to cause a denial of service (core dump) via a web page that begins with a "xFFxFE" byte sequence and a large number of CRLF sequences, as demonstrated using freeze.htm.
nvd
CVE-2003-0459MEDIUMCVSS 5.0v2.1.1v2.2.2+8 more2003-08-27
CVE-2003-0459 [MEDIUM] CVE-2003-0459: KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the
KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.
nvd
CVE-2002-1151HIGHCVSS 7.5v2.2.2v3.0+3 more2002-10-11
CVE-2002-1151 [HIGH] CVE-2002-1151: The cross-site scripting protection for Konqueror in KDE 2.2.2 and 3.0 through 3.0.3 does not proper
The cross-site scripting protection for Konqueror in KDE 2.2.2 and 3.0 through 3.0.3 does not properly initialize the domains on sub-frames and sub-iframes, which can allow remote attackers to execute script and steal cookies from subframes that are in other domains.
nvd
CVE-2002-0970HIGHCVSS 7.5v2.2.2v3.0+2 more2002-09-24
CVE-2002-0970 [HIGH] CVE-2002-0970: The SSL capability for Konqueror in KDE 3.0.2 and earlier does not verify the Basic Constraints for
The SSL capability for Konqueror in KDE 3.0.2 and earlier does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack.
nvd
← Previous2 / 2