Lucene search

K
nvd[email protected]NVD:CVE-2003-0692
HistoryOct 06, 2003 - 4:00 a.m.

CVE-2003-0692

2003-10-0604:00:00
web.nvd.nist.gov
1

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.4 Medium

AI Score

Confidence

Low

0.009 Low

EPSS

Percentile

82.9%

KDM in KDE 3.1.3 and earlier uses a weak session cookie generation algorithm that does not provide 128 bits of entropy, which allows attackers to guess session cookies via brute force methods and gain access to the user session.

Affected configurations

NVD
Node
kdekdeMatch1.1
OR
kdekdeMatch1.1.1
OR
kdekdeMatch1.1.2
OR
kdekdeMatch1.2
OR
kdekdeMatch2.0
OR
kdekdeMatch2.0.1
OR
kdekdeMatch2.0_beta
OR
kdekdeMatch2.1
OR
kdekdeMatch2.1.1
OR
kdekdeMatch2.1.2
OR
kdekdeMatch2.2
OR
kdekdeMatch2.2.1
OR
kdekdeMatch2.2.2
OR
kdekdeMatch3.0
OR
kdekdeMatch3.0.1
OR
kdekdeMatch3.0.2
OR
kdekdeMatch3.0.3
OR
kdekdeMatch3.0.3a
OR
kdekdeMatch3.0.4
OR
kdekdeMatch3.0.5
OR
kdekdeMatch3.0.5a
OR
kdekdeMatch3.0.5b
OR
kdekdeMatch3.1
OR
kdekdeMatch3.1.1
OR
kdekdeMatch3.1.1a
OR
kdekdeMatch3.1.2
OR
kdekdeMatch3.1.3

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.4 Medium

AI Score

Confidence

Low

0.009 Low

EPSS

Percentile

82.9%