Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23888
HistoryApr 10, 2020 - 12:39 a.m.

Remote Code Execution (RCE)

2020-04-1000:39:14
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.035 Low

EPSS

Percentile

91.6%

The kdelibs is vulnerable to Remote Code Execution (RCE). A flaw was found in the way the KDE CSS parser handled content for the CSS “style” attribute. A remote attacker could create a specially-crafted CSS equipped HTML page, which once visited by an unsuspecting user, could cause a denial of service (Konqueror crash) or, potentially, execute arbitrary code with the privileges of the user running Konqueror.

References