7.5
CVE-2005-0754
- EPSS 2.98%
- Veröffentlicht 22.04.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:11:42
- Erkennungen
Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Fedora Core Version core_3.0
Ubuntu ≫ Ubuntu Linux Version 4.1 Edition ia64
Ubuntu ≫ Ubuntu Linux Version 4.1 Edition ppc
Ubuntu ≫ Ubuntu Linux Version 5.04 Edition amd64
Ubuntu ≫ Ubuntu Linux Version 5.04 Edition i386
Ubuntu ≫ Ubuntu Linux Version 5.04 Edition powerpc
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.98% | 0.855 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.0-kdewebdev-kommander.diff
http://marc.info/?l=bugtraq&m=111419664411051&w=2
http://secunia.com/advisories/15060
http://www.kde.org/info/security/advisory-20050420-1.txt
http://www.securityfocus.com/bid/13313