10

CVE-2003-0690

KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5 module.

Data is provided by the National Vulnerability Database (NVD)
KdeKde Version1.1
KdeKde Version1.1.1
KdeKde Version1.1.2
KdeKde Version1.2
KdeKde Version2.0
KdeKde Version2.0.1
KdeKde Version2.0_beta
KdeKde Version2.1
KdeKde Version2.1.1
KdeKde Version2.1.2
KdeKde Version2.2
KdeKde Version2.2.1
KdeKde Version2.2.2
KdeKde Version3.0
KdeKde Version3.0.1
KdeKde Version3.0.2
KdeKde Version3.0.3
KdeKde Version3.0.3a
KdeKde Version3.0.4
KdeKde Version3.0.5
KdeKde Version3.0.5a
KdeKde Version3.0.5b
KdeKde Version3.1
KdeKde Version3.1.1
KdeKde Version3.1.1a
KdeKde Version3.1.2
KdeKde Version3.1.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.08% 0.832
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C