Kde Konqueror Embedded vulnerabilities
3 known vulnerabilities affecting kde/konqueror_embedded.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2003-0592HIGHCVSS 7.5v0.12004-04-15
CVE-2003-0592 [HIGH] CVE-2003-0592: Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie acces
Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target app
nvd
CVE-2003-0459MEDIUMCVSS 5.0v0.12003-08-27
CVE-2003-0459 [MEDIUM] CVE-2003-0459: KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the
KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.
nvd
CVE-2003-0370HIGHCVSS 7.5v0.12003-06-16
CVE-2003-0370 [HIGH] CVE-2003-0370: Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509
Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.
nvd