Show filters
210 Total Results
Displaying 131-140 of 210
Sort by:
Attacker Value
Unknown

CVE-2005-3624

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.
0
Attacker Value
Unknown

CVE-2005-4684

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Konqueror can associate a cookie with multiple domains when the DNS resolver has a non-root domain in its search list, which allows remote attackers to trick a user into accepting a cookie for a hostname formed via search-list expansion of the hostname entered by the user, or steal a cookie for an expanded hostname, as demonstrated by an attacker who operates an ap1.com Internet web site to steal cookies associated with an ap1.com.example.com intranet web site.
0
Attacker Value
Unknown

CVE-2005-2971

Disclosure Date: October 20, 2005 (last updated February 22, 2025)
Heap-based buffer overflow in the KWord RTF importer for KOffice 1.2.0 through 1.4.1 allows remote attackers to execute arbitrary code via a crafted RTF file.
0
Attacker Value
Unknown

CVE-2005-2494

Disclosure Date: September 06, 2005 (last updated February 22, 2025)
kcheckpass in KDE 3.2.0 up to 3.4.2 allows local users to gain root access via a symlink attack on lock files.
0
Attacker Value
Unknown

CVE-2005-2101

Disclosure Date: August 17, 2005 (last updated February 22, 2025)
langen2kvtml in KDE 3.0 to 3.4.2 creates insecure temporary files in /tmp with predictable names, which allows local users to overwrite arbitrary files.
0
Attacker Value
Unknown

CVE-2005-2097

Disclosure Date: August 16, 2005 (last updated February 22, 2025)
xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information.
0
Attacker Value
Unknown

CVE-2005-1852

Disclosure Date: July 26, 2005 (last updated February 22, 2025)
Multiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, GNU Gadu, CenterICQ, Kadu, and other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an incoming message.
0
Attacker Value
Unknown

CVE-2005-1920

Disclosure Date: July 26, 2005 (last updated February 22, 2025)
The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information.
Attacker Value
Unknown

CVE-2005-0011

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Interface (INDI) in KDE 3.3 to 3.3.2, allow local users and remote attackers to execute arbitrary code via stack-based buffer overflows.
0
Attacker Value
Unknown

CVE-2005-0205

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
KPPP 2.1.2 in KDE 3.1.5 and earlier, when setuid root without certain wrappers, does not properly close a privileged file descriptor for a domain socket, which allows local users to read and write to /etc/hosts and /etc/resolv.conf and gain control over DNS name resolution by opening a number of file descriptors before executing kppp.
0