Show filters
118 Total Results
Displaying 61-70 of 118
Sort by:
Attacker Value
Unknown

CVE-2005-0205

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
KPPP 2.1.2 in KDE 3.1.5 and earlier, when setuid root without certain wrappers, does not properly close a privileged file descriptor for a domain socket, which allows local users to read and write to /etc/hosts and /etc/resolv.conf and gain control over DNS name resolution by opening a number of file descriptors before executing kppp.
0
Attacker Value
Unknown

CVE-2005-1046

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Buffer overflow in the kimgio library for KDE 3.4.0 allows remote attackers to execute arbitrary code via a crafted PCX image file.
0
Attacker Value
Unknown

CVE-2005-0237

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
The International Domain Name (IDN) support in Konqueror 3.2.1 on KDE 3.2.1 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.
0
Attacker Value
Unknown

CVE-2005-0365

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
The dcopidlng script in KDE 3.2.x and 3.3.x creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.
0
Attacker Value
Unknown

CVE-2005-0078

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
The KDE screen saver in KDE before 3.0.5 does not properly check the return value from a certain function call, which allows attackers with physical access to cause a crash and access the desktop session.
0
Attacker Value
Unknown

CVE-2005-0404

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
KMail 1.7.1 in KDE 3.3.2 allows remote attackers to spoof email information, such as whether the email has been digitally signed or encrypted, via HTML formatted email.
0
Attacker Value
Unknown

CVE-2005-0206

Disclosure Date: April 27, 2005 (last updated February 22, 2025)
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
0
Attacker Value
Unknown

CVE-2005-0754

Disclosure Date: April 22, 2005 (last updated February 22, 2025)
Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2004-0888

Disclosure Date: January 27, 2005 (last updated February 22, 2025)
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
0
Attacker Value
Unknown

CVE-2004-0886

Disclosure Date: January 27, 2005 (last updated February 22, 2025)
Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.
0