Show filters
210 Total Results
Displaying 31-40 of 210
Sort by:
Attacker Value
Unknown
CVE-2020-9359
Disclosure Date: March 24, 2020 (last updated November 08, 2023)
KDE Okular before 1.10.0 allows code execution via an action link in a PDF document.
0
Attacker Value
Unknown
CVE-2019-18641
Disclosure Date: March 20, 2020 (last updated November 27, 2024)
Rock RMS before 1.8.6 mishandles vCard access control within the People/GetVCard/REST controller.
0
Attacker Value
Unknown
CVE-2018-19516
Disclosure Date: March 12, 2020 (last updated February 21, 2025)
messagepartthemes/default/defaultrenderer.cpp in messagelib in KDE Applications before 18.12.0 does not properly restrict the handling of an http-equiv="REFRESH" value.
0
Attacker Value
Unknown
CVE-2013-2213
Disclosure Date: February 11, 2020 (last updated February 21, 2025)
The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addons uses the GNU C Library rand function's linear congruential generator, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the generator output.
0
Attacker Value
Unknown
CVE-2013-2120
Disclosure Date: February 11, 2020 (last updated February 21, 2025)
The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a brute-force attack.
0
Attacker Value
Unknown
CVE-2012-4512
Disclosure Date: February 08, 2020 (last updated February 21, 2025)
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."
0
Attacker Value
Unknown
CVE-2014-9211
Disclosure Date: January 14, 2020 (last updated February 21, 2025)
ClickDesk version 4.3 and below has persistent cross site scripting
0
Attacker Value
Unknown
CVE-2013-4133
Disclosure Date: December 10, 2019 (last updated November 27, 2024)
kde-workspace before 4.10.5 has a memory leak in plasma desktop
0
Attacker Value
Unknown
CVE-2015-9323
Disclosure Date: August 16, 2019 (last updated November 27, 2024)
The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.
0
Attacker Value
Unknown
CVE-2019-14744
Disclosure Date: August 07, 2019 (last updated November 08, 2023)
In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.
0