Vulnerabilities (CVE)

Filtered by vendor Kde Subscribe
Total 193 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-0610 2 Kde, Suse 2 Kde, Suse Linux 2023-12-10 4.6 MEDIUM N/A
kfm as included with KDE 1.x can allow a local attacker to gain additional privileges via a symlink attack in the kfm cache directory in /tmp.
CVE-1999-1267 1 Kde 1 Kde 2023-12-10 5.0 MEDIUM N/A
KDE file manager (kfm) uses a TCP server for certain file operations, which allows remote attackers to modify arbitrary files by sending a copy command to the server.
CVE-2002-1224 1 Kde 1 Kde 2023-12-10 5.0 MEDIUM N/A
Directory traversal vulnerability in kpf for KDE 3.0.1 through KDE 3.0.3a allows remote attackers to read arbitrary files as the kpf user via a URL with a modified icon parameter.
CVE-2003-0355 2 Apple, Kde 2 Safari, Konqueror Embedded 2023-12-10 5.0 MEDIUM N/A
Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates.
CVE-2003-0692 1 Kde 1 Kde 2023-12-10 7.5 HIGH N/A
KDM in KDE 3.1.3 and earlier uses a weak session cookie generation algorithm that does not provide 128 bits of entropy, which allows attackers to guess session cookies via brute force methods and gain access to the user session.
CVE-1999-1269 1 Kde 1 Kde Beta 3 2023-12-10 2.1 LOW N/A
Screen savers in KDE beta 3 allows local users to overwrite arbitrary files via a symlink attack on the .kss.pid file.
CVE-2003-0459 2 Kde, Redhat 8 Konqueror, Konqueror Embedded, Analog Real-time Synthesizer and 5 more 2023-12-10 5.0 MEDIUM N/A
KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.
CVE-2004-0527 1 Kde 1 Konqueror 2023-12-10 5.0 MEDIUM N/A
KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.
CVE-2002-1393 1 Kde 1 Kde 2023-12-10 7.5 HIGH N/A
Multiple vulnerabilities in KDE 2 and KDE 3.x through 3.0.5 do not quote certain parameters that are inserted into a shell command, which could allow remote attackers to execute arbitrary commands via (1) URLs, (2) filenames, or (3) e-mail addresses.
CVE-1999-0781 3 Freebsd, Kde, Linux 3 Freebsd, Kde, Linux Kernel 2023-12-10 7.2 HIGH N/A
KDE allows local users to execute arbitrary commands by setting the KDEDIR environmental variable to modify the search path that KDE uses to locate its executables.
CVE-2003-0988 1 Kde 1 Kde 2023-12-10 7.5 HIGH N/A
Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows attackers to execute arbitrary code via a VCF file.
CVE-2002-1151 1 Kde 2 Kde, Konqueror 2023-12-10 7.5 HIGH N/A
The cross-site scripting protection for Konqueror in KDE 2.2.2 and 3.0 through 3.0.3 does not properly initialize the domains on sub-frames and sub-iframes, which can allow remote attackers to execute script and steal cookies from subframes that are in other domains.
CVE-1999-1270 1 Kde 1 Kde 2023-12-10 4.6 MEDIUM N/A
KMail in KDE 1.0 provides a PGP passphrase as a command line argument to other programs, which could allow local users to obtain the passphrase and compromise the PGP keys of other users by viewing the arguments via programs that list process information, such as ps.