Show filters
30 Total Results
Displaying 11-20 of 30
Sort by:
Attacker Value
Unknown

CVE-2004-1171

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
KDE 3.2.x and 3.3.0 through 3.3.2, when saving credentials that are (1) manually entered by the user or (2) created by the SMB protocol handler, stores those credentials for plaintext in the user's .desktop file, which may be created with world-readable permissions, which could allow local users to obtain usernames and passwords for remote resources such as SMB shares.
0
Attacker Value
Unknown

CVE-2004-1125

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PDF file that causes the boundaries of a maskColors array to be exceeded.
0
Attacker Value
Unknown

CVE-2004-1491

Disclosure Date: December 31, 2004 (last updated October 04, 2023)
Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code via a shortcut or launcher that contains an Exec entry.
0
Attacker Value
Unknown

CVE-2004-0803

Disclosure Date: December 23, 2004 (last updated February 22, 2025)
Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files.
0
Attacker Value
Unknown

CVE-2004-0746

Disclosure Date: October 20, 2004 (last updated February 22, 2025)
Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.
0
Attacker Value
Unknown

CVE-2004-0689

Disclosure Date: September 28, 2004 (last updated February 22, 2025)
KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.
Attacker Value
Unknown

CVE-2003-0690

Disclosure Date: October 06, 2003 (last updated February 22, 2025)
KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5 module.
0
Attacker Value
Unknown

CVE-2003-0692

Disclosure Date: October 06, 2003 (last updated February 22, 2025)
KDM in KDE 3.1.3 and earlier uses a weak session cookie generation algorithm that does not provide 128 bits of entropy, which allows attackers to guess session cookies via brute force methods and gain access to the user session.
0
Attacker Value
Unknown

CVE-2003-0204

Disclosure Date: May 05, 2003 (last updated February 22, 2025)
KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF files, related to missing -dPARANOIDSAFER and -dSAFER arguments when using the kghostview Ghostscript viewer.
0
Attacker Value
Unknown

CVE-2002-1393

Disclosure Date: January 17, 2003 (last updated February 22, 2025)
Multiple vulnerabilities in KDE 2 and KDE 3.x through 3.0.5 do not quote certain parameters that are inserted into a shell command, which could allow remote attackers to execute arbitrary commands via (1) URLs, (2) filenames, or (3) e-mail addresses.
0