Lucene search

K

Kde Security Vulnerabilities

cve
cve

CVE-2002-2333

Buffer overflow in konqueror in KDE 2.1 through 3.0 and 3.0.2 allows remote attackers to cause a denial of service (crash) via an IMG tag with large width and height...

7.3AI Score

0.006EPSS

2022-10-03 04:23 PM
18
cve
cve

CVE-2017-9604

KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the...

7.5CVSS

6.5AI Score

0.002EPSS

2022-10-03 04:23 PM
28
cve
cve

CVE-2010-0923

Race condition in workspace/krunner/lock/lockdlg.cc in the KRunner lock module in kdebase in KDE SC 4.4.0 allows physically proximate attackers to bypass KScreenSaver screen locking and access an unattended workstation by pressing the Enter key at a certain time, related to multiple forked...

6.7AI Score

0.0005EPSS

2022-10-03 04:21 PM
27
cve
cve

CVE-2018-19516

messagepartthemes/default/defaultrenderer.cpp in messagelib in KDE Applications before 18.12.0 does not properly restrict the handling of an http-equiv="REFRESH"...

5.3CVSS

5AI Score

0.001EPSS

2020-03-12 09:15 PM
49
cve
cve

CVE-2013-2120

The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a brute-force...

8.4CVSS

8.8AI Score

0.002EPSS

2020-02-11 08:15 PM
24
cve
cve

CVE-2013-2213

The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addons uses the GNU C Library rand function's linear congruential generator, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the generator...

5.5CVSS

5.3AI Score

0.0005EPSS

2020-02-11 08:15 PM
25
cve
cve

CVE-2012-4512

The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type...

8.8CVSS

8AI Score

0.02EPSS

2020-02-08 07:15 PM
96
cve
cve

CVE-2013-4133

kde-workspace before 4.10.5 has a memory leak in plasma...

7.5CVSS

7.3AI Score

0.008EPSS

2019-12-10 03:15 PM
30
cve
cve

CVE-2018-19120

The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leading to disclosure of the source IP...

7.5CVSS

7.2AI Score

0.002EPSS

2018-11-29 09:29 PM
26
cve
cve

CVE-2016-7787

A maliciously crafted command line for kdesu can result in the user only seeing part of the commands that will actually get executed as super...

4.9CVSS

5.2AI Score

0.002EPSS

2016-12-23 10:59 PM
24
cve
cve

CVE-2016-3100

kinit in KDE Frameworks before 5.23.0 uses weak permissions (644) for /tmp/xauth-xxx-_y, which allows local users to obtain X11 cookies of other users and consequently capture keystrokes and possibly gain privileges by reading the...

8.4CVSS

8.1AI Score

0.001EPSS

2016-07-13 03:59 PM
19
cve
cve

CVE-2015-1308

kde-workspace 4.2.0 and plasma-workspace before 5.1.95 allows remote attackers to obtain input events, and consequently obtain passwords, by leveraging access to the X server when the screen is...

6.8AI Score

0.003EPSS

2015-01-26 03:59 PM
25
cve
cve

CVE-2013-7252

kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes it easier for attackers to guess passwords via a codebook...

6.4AI Score

0.004EPSS

2015-01-18 06:59 PM
20
cve
cve

CVE-2014-8600

Multiple cross-site scripting (XSS) vulnerabilities in KDE-Runtime 4.14.3 and earlier, kwebkitpart 1.3.4 and earlier, and kio-extras 5.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via a crafted URI using the (1) zip, (2) trash, (3) tar, (4) thumbnail, (5) smtps,...

5.4AI Score

0.003EPSS

2014-12-08 11:59 AM
35
cve
cve

CVE-2014-8651

The KDE Clock KCM policykit helper in kde-workspace before 4.11.14 and plasma-desktop before 5.1.1 allows local users to gain privileges via a crafted ntpUtility (ntp utility name)...

6.2AI Score

0.0004EPSS

2014-12-06 09:59 PM
31
cve
cve

CVE-2011-2725

Directory traversal vulnerability in Ark 4.7.x and earlier allows remote attackers to delete and force the display of arbitrary files via .. (dot dot) sequences in a zip...

6.5AI Score

0.009EPSS

2014-02-04 11:55 PM
32
cve
cve

CVE-2013-4132

KDE-Workspace 4.10.5 and earlier does not properly handle the return value of the glibc 2.17 crypt and pw_encrypt functions, which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via (1) an invalid salt or a (2) DES or (3) MD5 encrypted password, when...

7.4AI Score

0.004EPSS

2013-09-16 07:14 PM
28
cve
cve

CVE-2012-4515

Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by accessing an iframe when it is being...

8.7AI Score

0.03EPSS

2012-11-11 01:00 PM
31
cve
cve

CVE-2012-4514

rendering/render_replaced.cpp in Konqueror in KDE before 4.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted web page, related to "trying to reuse a frame with a null...

7.9AI Score

0.025EPSS

2012-11-11 01:00 PM
32
2
cve
cve

CVE-2012-4513

khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via large canvas dimensions, which leads to an unexpected sign extension and a heap-based buffer...

8.3AI Score

0.074EPSS

2012-11-11 01:00 PM
29
cve
cve

CVE-2012-3413

The HTMLQuoteColorer::process function in messageviewer/htmlquotecolorer.cpp in KDE PIM 4.6 through 4.8 does not disable JavaScript, Java, and Plugins, which allows remote attackers to inject arbitrary web script or HTML via a crafted...

6.2AI Score

0.005EPSS

2012-08-07 08:55 PM
22
cve
cve

CVE-2011-3365

The KDE SSL Wrapper (KSSL) API in KDE SC 4.6.0 through 4.7.1, and possibly earlier versions, does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich...

6.7AI Score

0.006EPSS

2011-11-29 05:55 PM
39
cve
cve

CVE-2011-1586

Directory traversal vulnerability in the KGetMetalink::File::isValidNameAttr function in ui/metalinkcreator/metalinker.cpp in KGet in KDE SC 4.6.2 and earlier allows remote attackers to create arbitrary files via a .. (dot dot) in the name attribute of a file element in a metalink file. NOTE:...

6.9AI Score

0.006EPSS

2011-04-27 12:55 AM
32
cve
cve

CVE-2011-1168

Cross-site scripting (XSS) vulnerability in the KHTMLPart::htmlError function in khtml/khtml_part.cpp in Konqueror in KDE SC 4.4.0 through 4.6.1 allows remote attackers to inject arbitrary web script or HTML via the URI in a URL corresponding to an unavailable web...

5.8AI Score

0.007EPSS

2011-04-18 06:55 PM
37
cve
cve

CVE-2010-2575

Heap-based buffer overflow in the RLE decompression functionality in the TranscribePalmImageToJPEG function in generators/plucker/inplug/image.cpp in Okular in KDE SC 4.3.0 through 4.5.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via....

8AI Score

0.06EPSS

2010-08-30 09:00 PM
28
cve
cve

CVE-2010-1511

KGet 2.4.2 in KDE SC 4.0.0 through 4.4.3 does not properly request download confirmation from the user, which makes it easier for remote attackers to overwrite arbitrary files via a crafted metalink...

9.2AI Score

0.008EPSS

2010-05-17 09:00 PM
37
cve
cve

CVE-2010-1000

Directory traversal vulnerability in KGet in KDE SC 4.0.0 through 4.4.3 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink...

9.3AI Score

0.006EPSS

2010-05-17 09:00 PM
31
cve
cve

CVE-2010-0436

Race condition in backend/ctrl.c in KDM in KDE Software Compilation (SC) 2.2.0 through 4.4.2 allows local users to change the permissions of arbitrary files, and consequently gain privileges, by blocking the removal of a certain directory that contains a control socket, related to improper...

8.9AI Score

0.0004EPSS

2010-04-15 05:30 PM
41
cve
cve

CVE-2008-5698

HTMLTokenizer::scriptHandler in Konqueror in KDE 3.5.9 and 3.5.10 allows remote attackers to cause a denial of service (application crash) via an invalid document.load call that triggers use of a deleted object. NOTE: some of these details are obtained from third party...

6.6AI Score

0.015EPSS

2008-12-22 03:30 PM
29
cve
cve

CVE-2008-1670

Heap-based buffer overflow in the progressive PNG Image loader (decoders/pngloader.cpp) in KHTML in KDE 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted...

7.6AI Score

0.039EPSS

2008-04-28 05:05 PM
24
cve
cve

CVE-2008-1671

start_kdeinit in KDE 3.5.5 through 3.5.9, when installed setuid root, allows local users to cause a denial of service and possibly execute arbitrary code via "user-influenceable input" (probably command-line arguments) that cause start_kdeinit to send SIGUSR1 signals to other...

7AI Score

0.0004EPSS

2008-04-28 05:05 PM
25
cve
cve

CVE-2007-5963

Unspecified vulnerability in kdebase allows local users to cause a denial of service (KDM login inaccessible, or resource consumption) via unknown...

5.8AI Score

0.0004EPSS

2007-12-19 11:46 PM
28
cve
cve

CVE-2007-4569

backend/session.c in KDM in KDE 3.3.0 through 3.5.7, when autologin is configured and "shutdown with password" is enabled, allows remote attackers to bypass the password requirement and login to arbitrary accounts via unspecified...

6.6AI Score

0.002EPSS

2007-09-21 07:17 PM
32
cve
cve

CVE-2006-7139

Kmail 1.9.1 on KDE 3.5.2, with "Prefer HTML to Plain Text" enabled, allows remote attackers to cause a denial of service (crash) via an HTML e-mail with certain table and frameset tags that trigger a segmentation fault, possibly involving invalid free or delete...

6.8AI Score

0.032EPSS

2007-03-07 08:19 PM
26
cve
cve

CVE-2007-0104

The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory...

6.9AI Score

0.068EPSS

2007-01-09 12:28 AM
30
cve
cve

CVE-2006-2933

kdesktop_lock in kdebase before 3.1.3-5.11 for KDE in Red Hat Enterprise Linux (RHEL) 3 does not properly terminate, which can prevent the screensaver from activating or prevent users from manually locking the...

6.4AI Score

0.001EPSS

2006-07-27 10:04 PM
29
cve
cve

CVE-2006-2449

KDE Display Manager (KDM) in KDE 3.2.0 up to 3.5.3 allows local users to read arbitrary files via a symlink attack related to the session type for...

5.9AI Score

0.001EPSS

2006-06-15 10:02 AM
29
cve
cve

CVE-2006-0019

Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded...

7.6AI Score

0.173EPSS

2006-01-20 09:03 PM
45
cve
cve

CVE-2005-2494

kcheckpass in KDE 3.2.0 up to 3.4.2 allows local users to gain root access via a symlink attack on lock...

8.8AI Score

0.001EPSS

2005-09-06 11:03 PM
33
cve
cve

CVE-2005-2101

langen2kvtml in KDE 3.0 to 3.4.2 creates insecure temporary files in /tmp with predictable names, which allows local users to overwrite arbitrary...

6.2AI Score

0.001EPSS

2005-08-17 04:00 AM
29
cve
cve

CVE-2005-1920

The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive...

7.5CVSS

7.3AI Score

0.003EPSS

2005-07-26 04:00 AM
37
cve
cve

CVE-2005-1852

Multiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, GNU Gadu, CenterICQ, Kadu, and other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an incoming...

6.4AI Score

0.068EPSS

2005-07-26 04:00 AM
41
cve
cve

CVE-2005-1046

Buffer overflow in the kimgio library for KDE 3.4.0 allows remote attackers to execute arbitrary code via a crafted PCX image...

7.4AI Score

0.136EPSS

2005-05-02 04:00 AM
38
cve
cve

CVE-2005-0205

KPPP 2.1.2 in KDE 3.1.5 and earlier, when setuid root without certain wrappers, does not properly close a privileged file descriptor for a domain socket, which allows local users to read and write to /etc/hosts and /etc/resolv.conf and gain control over DNS name resolution by opening a number of...

6.1AI Score

0.0004EPSS

2005-05-02 04:00 AM
29
cve
cve

CVE-2005-0365

The dcopidlng script in KDE 3.2.x and 3.3.x creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink...

5.9AI Score

0.0004EPSS

2005-05-02 04:00 AM
32
cve
cve

CVE-2005-0078

The KDE screen saver in KDE before 3.0.5 does not properly check the return value from a certain function call, which allows attackers with physical access to cause a crash and access the desktop...

6AI Score

0.002EPSS

2005-05-02 04:00 AM
33
cve
cve

CVE-2005-0404

KMail 1.7.1 in KDE 3.3.2 allows remote attackers to spoof email information, such as whether the email has been digitally signed or encrypted, via HTML formatted...

6.5AI Score

0.037EPSS

2005-05-02 04:00 AM
24
cve
cve

CVE-2005-0237

The International Domain Name (IDN) support in Konqueror 3.2.1 on KDE 3.2.1 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing.....

6.2AI Score

0.011EPSS

2005-05-02 04:00 AM
36
cve
cve

CVE-2005-0011

Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Interface (INDI) in KDE 3.3 to 3.3.2, allow local users and remote attackers to execute arbitrary code via stack-based buffer...

7.5AI Score

0.007EPSS

2005-05-02 04:00 AM
23
cve
cve

CVE-2005-0206

The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original...

6.7AI Score

0.07EPSS

2005-04-27 04:00 AM
24
Total number of security vulnerabilities83