Show filters
210 Total Results
Displaying 91-100 of 210
Sort by:
Attacker Value
Unknown

CVE-2010-0923

Disclosure Date: March 03, 2010 (last updated October 04, 2023)
Race condition in workspace/krunner/lock/lockdlg.cc in the KRunner lock module in kdebase in KDE SC 4.4.0 allows physically proximate attackers to bypass KScreenSaver screen locking and access an unattended workstation by pressing the Enter key at a certain time, related to multiple forked processes.
0
Attacker Value
Unknown

CVE-2009-4035

Disclosure Date: December 21, 2009 (last updated October 04, 2023)
The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to execute arbitrary code via a PDF file with a crafted Type 1 font that can produce a negative value, leading to a signed-to-unsigned integer conversion error and a buffer overflow.
0
Attacker Value
Unknown

CVE-2009-2702

Disclosure Date: September 08, 2009 (last updated October 04, 2023)
KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
0
Attacker Value
Unknown

CVE-2009-2896

Disclosure Date: August 20, 2009 (last updated October 04, 2023)
Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a subtitle (.srt) playlist file. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2009-2537

Disclosure Date: July 20, 2009 (last updated October 04, 2023)
KDE Konqueror allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.
0
Attacker Value
Unknown

CVE-2008-5712

Disclosure Date: December 24, 2008 (last updated October 04, 2023)
The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via (1) a long COLOR attribute in an HR element; or a long (a) BGCOLOR or (b) BORDERCOLOR attribute in a (2) TABLE, (3) TD, or (4) TR element. NOTE: the FONT vector is already covered by CVE-2008-4514.
0
Attacker Value
Unknown

CVE-2008-5698

Disclosure Date: December 22, 2008 (last updated October 04, 2023)
HTMLTokenizer::scriptHandler in Konqueror in KDE 3.5.9 and 3.5.10 allows remote attackers to cause a denial of service (application crash) via an invalid document.load call that triggers use of a deleted object. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-4382

Disclosure Date: October 02, 2008 (last updated October 04, 2023)
Konqueror in KDE 3.5.9 allows remote attackers to cause a denial of service (application crash) via Javascript that calls the alert function with a URL-encoded string of a large number of invalid characters.
0
Attacker Value
Unknown

CVE-2008-1670

Disclosure Date: April 28, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in the progressive PNG Image loader (decoders/pngloader.cpp) in KHTML in KDE 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted image.
0
Attacker Value
Unknown

CVE-2008-1671

Disclosure Date: April 28, 2008 (last updated October 04, 2023)
start_kdeinit in KDE 3.5.5 through 3.5.9, when installed setuid root, allows local users to cause a denial of service and possibly execute arbitrary code via "user-influenceable input" (probably command-line arguments) that cause start_kdeinit to send SIGUSR1 signals to other processes.
0