5

CVE-2004-1145

Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows remote attackers to bypass sandbox restrictions and read or write arbitrary files.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ethereal GroupEthereal Version0.9
Ethereal GroupEthereal Version0.9.1
Ethereal GroupEthereal Version0.9.2
Ethereal GroupEthereal Version0.9.3
Ethereal GroupEthereal Version0.9.4
Ethereal GroupEthereal Version0.9.5
Ethereal GroupEthereal Version0.9.6
Ethereal GroupEthereal Version0.9.7
Ethereal GroupEthereal Version0.9.8
Ethereal GroupEthereal Version0.9.9
Ethereal GroupEthereal Version0.9.10
Ethereal GroupEthereal Version0.9.11
Ethereal GroupEthereal Version0.9.12
Ethereal GroupEthereal Version0.9.13
Ethereal GroupEthereal Version0.9.14
Ethereal GroupEthereal Version0.9.15
Ethereal GroupEthereal Version0.9.16
Ethereal GroupEthereal Version0.10
Ethereal GroupEthereal Version0.10.1
Ethereal GroupEthereal Version0.10.2
Ethereal GroupEthereal Version0.10.3
Ethereal GroupEthereal Version0.10.4
Ethereal GroupEthereal Version0.10.5
Ethereal GroupEthereal Version0.10.6
Ethereal GroupEthereal Version0.10.7
SgiPropack Version3.0
ConectivaLinux Version9.0
ConectivaLinux Version10.0
AltlinuxAlt Linux Version2.3 Editioncompact
AltlinuxAlt Linux Version2.3 Editionjunior
DebianDebian Linux Version3.0 Editionalpha
DebianDebian Linux Version3.0 Editionarm
DebianDebian Linux Version3.0 Editionhppa
DebianDebian Linux Version3.0 Editionia-32
DebianDebian Linux Version3.0 Editionia-64
DebianDebian Linux Version3.0 Editionm68k
DebianDebian Linux Version3.0 Editionmips
DebianDebian Linux Version3.0 Editionmipsel
DebianDebian Linux Version3.0 Editionppc
DebianDebian Linux Version3.0 Editions-390
DebianDebian Linux Version3.0 Editionsparc
RedhatEnterprise Linux Version2.1 Editionadvanced_server
RedhatEnterprise Linux Version2.1 Editionadvanced_server_ia64
RedhatEnterprise Linux Version2.1 Editionenterprise_server
RedhatEnterprise Linux Version2.1 Editionenterprise_server_ia64
RedhatEnterprise Linux Version2.1 Editionworkstation
RedhatEnterprise Linux Version2.1 Editionworkstation_ia64
RedhatEnterprise Linux Version3.0 Editionadvanced_server
RedhatEnterprise Linux Version3.0 Editionenterprise_server
RedhatEnterprise Linux Version3.0 Editionworkstation_server
RedhatLinux Advanced Workstation Version2.1 Editionia64
RedhatLinux Advanced Workstation Version2.1 Editionitanium_processor
SuseSuse Linux Version8.0
SuseSuse Linux Version8.0 Editioni386
SuseSuse Linux Version8.1
SuseSuse Linux Version8.2
SuseSuse Linux Version9.0
SuseSuse Linux Version9.0 Editionx86_64
SuseSuse Linux Version9.1
SuseSuse Linux Version9.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.72% 0.903
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N