Lucene search

K
cveRedhatCVE-2005-0237
HistoryMay 02, 2005 - 4:00 a.m.

CVE-2005-0237

2005-05-0204:00:00
redhat
web.nvd.nist.gov
44
cve-2005-0237
international domain name
idn
konqueror
remote attackers
spoofing
punycode
phishing attacks
ssl certificates
homograph characters

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.2

Confidence

Low

EPSS

0.011

Percentile

84.1%

The International Domain Name (IDN) support in Konqueror 3.2.1 on KDE 3.2.1 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.

Affected configurations

Nvd
Node
kdekonquerorMatch3.2.1
Node
kdekdeMatch3.2.1
VendorProductVersionCPE
kdekonqueror3.2.1cpe:2.3:a:kde:konqueror:3.2.1:*:*:*:*:*:*:*
kdekde3.2.1cpe:2.3:o:kde:kde:3.2.1:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.2

Confidence

Low

EPSS

0.011

Percentile

84.1%