Show filters
210 Total Results
Displaying 11-20 of 210
Sort by:
Attacker Value
Unknown
CVE-2024-1433
Disclosure Date: February 11, 2024 (last updated September 06, 2024)
A vulnerability, which was classified as problematic, was found in KDE Plasma Workspace up to 5.93.0. This affects the function EventPluginsManager::enabledPlugins of the file components/calendar/eventpluginsmanager.cpp of the component Theme File Handler. The manipulation of the argument pluginId leads to path traversal. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The patch is named 6cdf42916369ebf4ad5bd876c4dfa0170d7b2f01. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-253407. NOTE: This requires write access to user's home or the installation of third party global themes.
0
Attacker Value
Unknown
CVE-2023-46347
Disclosure Date: October 25, 2023 (last updated November 02, 2023)
In the module "Step by Step products Pack" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a guest can perform SQL injection. The method `NdkSpack::getPacks()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.
0
Attacker Value
Unknown
CVE-2021-4338
Disclosure Date: June 07, 2023 (last updated October 08, 2023)
The 404 to 301 plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the open_redirect & save_redirect functions in versions up to, and including, 3.0.7. This makes it possible for authenticated attackers to view, create and edit redirections.
0
Attacker Value
Unknown
CVE-2022-24986
Disclosure Date: February 26, 2022 (last updated October 07, 2023)
KDE KCron through 21.12.2 uses a temporary file in /tmp when saving, but reuses the filename during an editing session. Thus, someone watching it be created the first time could potentially intercept the file the following time, enabling that person to run unauthorized commands.
0
Attacker Value
Unknown
CVE-2022-23853
Disclosure Date: February 11, 2022 (last updated October 07, 2023)
The LSP (Language Server Protocol) plugin in KDE Kate before 21.12.2 and KTextEditor before 5.91.0 tries to execute the associated LSP server binary when opening a file of a given type. If this binary is absent from the PATH, it will try running the LSP server binary in the directory of the file that was just opened (due to a misunderstanding of the QProcess API, that was never intended). This can be an untrusted directory.
0
Attacker Value
Unknown
CVE-2021-38372
Disclosure Date: August 10, 2021 (last updated November 28, 2024)
In KDE Trojita 0.7, man-in-the-middle attackers can create new folders because untagged responses from an IMAP server are accepted before STARTTLS.
0
Attacker Value
Unknown
CVE-2021-38373
Disclosure Date: August 10, 2021 (last updated November 28, 2024)
In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked.
0
Attacker Value
Unknown
CVE-2021-36083
Disclosure Date: July 01, 2021 (last updated November 28, 2024)
KDE KImageFormats 5.70.0 through 5.81.0 has a stack-based buffer overflow in XCFImageFormat::loadTileRLE.
0
Attacker Value
Unknown
CVE-2021-31855
Disclosure Date: June 02, 2021 (last updated November 09, 2023)
KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g., an IMAP server) causes KMail to upload the decrypted content of the message to the remote server. With a crafted message, a user could be tricked into decrypting an encrypted message and then deleting an attachment attached to this message. If the attacker has access to the messages stored on the email server, then the attacker could read the decrypted content of the encrypted message. This occurs in ViewerPrivate::deleteAttachment in messageviewer/src/viewer/viewer_p.cpp.
0
Attacker Value
Unknown
CVE-2021-28117
Disclosure Date: March 20, 2021 (last updated November 17, 2023)
libdiscover/backends/KNSBackend/KNSResource.cpp in KDE Discover before 5.21.3 automatically creates links to potentially dangerous URLs (that are neither https:// nor http://) based on the content of the store.kde.org web site. (5.18.7 is also a fixed version.)
0