Show filters
210 Total Results
Displaying 31-40 of 210
Sort by:
Attacker Value
Unknown

CVE-2020-9359

Disclosure Date: March 24, 2020 (last updated November 08, 2023)
KDE Okular before 1.10.0 allows code execution via an action link in a PDF document.
Attacker Value
Unknown

CVE-2019-18641

Disclosure Date: March 20, 2020 (last updated November 27, 2024)
Rock RMS before 1.8.6 mishandles vCard access control within the People/GetVCard/REST controller.
Attacker Value
Unknown

CVE-2018-19516

Disclosure Date: March 12, 2020 (last updated February 21, 2025)
messagepartthemes/default/defaultrenderer.cpp in messagelib in KDE Applications before 18.12.0 does not properly restrict the handling of an http-equiv="REFRESH" value.
Attacker Value
Unknown

CVE-2013-2213

Disclosure Date: February 11, 2020 (last updated February 21, 2025)
The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addons uses the GNU C Library rand function's linear congruential generator, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the generator output.
Attacker Value
Unknown

CVE-2013-2120

Disclosure Date: February 11, 2020 (last updated February 21, 2025)
The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a brute-force attack.
Attacker Value
Unknown

CVE-2012-4512

Disclosure Date: February 08, 2020 (last updated February 21, 2025)
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."
Attacker Value
Unknown

CVE-2014-9211

Disclosure Date: January 14, 2020 (last updated February 21, 2025)
ClickDesk version 4.3 and below has persistent cross site scripting
Attacker Value
Unknown

CVE-2013-4133

Disclosure Date: December 10, 2019 (last updated November 27, 2024)
kde-workspace before 4.10.5 has a memory leak in plasma desktop
Attacker Value
Unknown

CVE-2015-9323

Disclosure Date: August 16, 2019 (last updated November 27, 2024)
The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.
Attacker Value
Unknown

CVE-2019-14744

Disclosure Date: August 07, 2019 (last updated November 08, 2023)
In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.