Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown

CVE-2012-4514

Disclosure Date: November 11, 2012 (last updated October 05, 2023)
rendering/render_replaced.cpp in Konqueror in KDE before 4.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted web page, related to "trying to reuse a frame with a null part."
0
Attacker Value
Unknown

CVE-2007-0104

Disclosure Date: January 09, 2007 (last updated October 04, 2023)
The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1) crafted catalog dictionary or (2) a crafted Pages attribute that references an invalid page tree node.
0
Attacker Value
Unknown

CVE-2006-2449

Disclosure Date: June 15, 2006 (last updated October 04, 2023)
KDE Display Manager (KDM) in KDE 3.2.0 up to 3.5.3 allows local users to read arbitrary files via a symlink attack related to the session type for login.
0
Attacker Value
Unknown

CVE-2006-0019

Disclosure Date: January 20, 2006 (last updated February 22, 2025)
Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI.
0
Attacker Value
Unknown

CVE-2005-2494

Disclosure Date: September 06, 2005 (last updated February 22, 2025)
kcheckpass in KDE 3.2.0 up to 3.4.2 allows local users to gain root access via a symlink attack on lock files.
0
Attacker Value
Unknown

CVE-2005-2101

Disclosure Date: August 17, 2005 (last updated February 22, 2025)
langen2kvtml in KDE 3.0 to 3.4.2 creates insecure temporary files in /tmp with predictable names, which allows local users to overwrite arbitrary files.
0
Attacker Value
Unknown

CVE-2005-0237

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
The International Domain Name (IDN) support in Konqueror 3.2.1 on KDE 3.2.1 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.
0
Attacker Value
Unknown

CVE-2005-0206

Disclosure Date: April 27, 2005 (last updated February 22, 2025)
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
0
Attacker Value
Unknown

CVE-2005-0754

Disclosure Date: April 22, 2005 (last updated February 22, 2025)
Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2004-0888

Disclosure Date: January 27, 2005 (last updated February 22, 2025)
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
0