Show filters
118 Total Results
Displaying 11-20 of 118
Sort by:
Attacker Value
Unknown
CVE-2017-6410
Disclosure Date: March 02, 2017 (last updated November 26, 2024)
kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.
0
Attacker Value
Unknown
CVE-2016-7787
Disclosure Date: December 23, 2016 (last updated November 25, 2024)
A maliciously crafted command line for kdesu can result in the user only seeing part of the commands that will actually get executed as super user.
0
Attacker Value
Unknown
CVE-2016-3100
Disclosure Date: July 13, 2016 (last updated November 25, 2024)
kinit in KDE Frameworks before 5.23.0 uses weak permissions (644) for /tmp/xauth-xxx-_y, which allows local users to obtain X11 cookies of other users and consequently capture keystrokes and possibly gain privileges by reading the file.
0
Attacker Value
Unknown
CVE-2015-4386
Disclosure Date: June 15, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in unspecified administration pages in the EntityBulkDelete module 7.x-1.0 for Drupal allow remote attackers to inject arbitrary web script or HTML via unknown vectors involving creating or editing (1) comments, (2) taxonomy terms, or (3) nodes.
0
Attacker Value
Unknown
CVE-2015-1308
Disclosure Date: January 26, 2015 (last updated October 05, 2023)
kde-workspace 4.2.0 and plasma-workspace before 5.1.95 allows remote attackers to obtain input events, and consequently obtain passwords, by leveraging access to the X server when the screen is locked.
0
Attacker Value
Unknown
CVE-2013-7252
Disclosure Date: January 18, 2015 (last updated October 05, 2023)
kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes it easier for attackers to guess passwords via a codebook attack.
0
Attacker Value
Unknown
CVE-2014-8600
Disclosure Date: December 08, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in KDE-Runtime 4.14.3 and earlier, kwebkitpart 1.3.4 and earlier, and kio-extras 5.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via a crafted URI using the (1) zip, (2) trash, (3) tar, (4) thumbnail, (5) smtps, (6) smtp, (7) smb, (8) remote, (9) recentdocuments, (10) nntps, (11) nntp, (12) network, (13) mbox, (14) ldaps, (15) ldap, (16) fonts, (17) file, (18) desktop, (19) cgi, (20) bookmarks, or (21) ar scheme, which is not properly handled in an error message.
0
Attacker Value
Unknown
CVE-2014-8651
Disclosure Date: December 06, 2014 (last updated October 05, 2023)
The KDE Clock KCM policykit helper in kde-workspace before 4.11.14 and plasma-desktop before 5.1.1 allows local users to gain privileges via a crafted ntpUtility (ntp utility name) argument.
0
Attacker Value
Unknown
CVE-2014-5033
Disclosure Date: August 19, 2014 (last updated October 05, 2023)
KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."
0
Attacker Value
Unknown
CVE-2014-3494
Disclosure Date: July 01, 2014 (last updated October 05, 2023)
kio/usernotificationhandler.cpp in the POP3 kioslave in kdelibs 4.10.95 before 4.13.3 does not properly generate warning notifications, which allows man-in-the-middle attackers to obtain sensitive information via an invalid certificate.
0