5

CVE-2003-0459

KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
KdeKonqueror Version2.1.1
KdeKonqueror Version2.2.2
KdeKonqueror Version3.0
KdeKonqueror Version3.0.1
KdeKonqueror Version3.0.2
KdeKonqueror Version3.0.3
KdeKonqueror Version3.0.5
KdeKonqueror Version3.1
KdeKonqueror Version3.1.1
KdeKonqueror Version3.1.2
KdeKonqueror Embedded Version0.1
RedhatAnalog Real-time Synthesizer Version2.1.1-5 Editioni386
RedhatAnalog Real-time Synthesizer Version2.2-11 Editioni386
RedhatAnalog Real-time Synthesizer Version2.2-11 Editionia64
RedhatKdebase Version3.0.3-13 Editioni386
RedhatKdebase Version3.0.3-13 Editioni386_dev
RedhatKdelibs Version2.1.1-5 Editioni386
RedhatKdelibs Version2.2-11 Editioni386
RedhatKdelibs Version2.2-11 Editionia64
RedhatKdelibs Version3.0.0-10 Editioni386
RedhatKdelibs Version3.1-10 Editioni386
RedhatKdelibs Devel Version2.1.1-5 Editioni386_dev
RedhatKdelibs Devel Version2.2-11 Editioni386_dev
RedhatKdelibs Devel Version2.2-11 Editionia64_dev
RedhatKdelibs Devel Version3.0.0-10 Editioni386_dev
RedhatKdelibs Devel Version3.0.3-8 Editioni386_dev
RedhatKdelibs Devel Version3.1-10 Editioni386_dev
RedhatKdelibs Sound Version2.1.1-5 Editioni386_sound
RedhatKdelibs Sound Version2.2-11 Editioni386_sound
RedhatKdelibs Sound Version2.2-11 Editionia64_sound
RedhatKdelibs Sound Devel Version2.1.1-5 Editioni386_sound_dev
RedhatKdelibs Sound Devel Version2.2-11 Editioni386_sound_dev
RedhatKdelibs Sound Devel Version2.2-11 Editionia64_sound_dev
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.53% 0.797
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N