CVE-2011-1094
- EPSS 0.81%
- Published 16.03.2011 22:55:04
- Last modified 11.04.2025 00:51:21
kio/kio/tcpslavebase.cpp in KDE KSSL in kdelibs before 4.6.1 does not properly verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via...
CVE-2006-4811
- EPSS 17.4%
- Published 18.10.2006 17:07:00
- Last modified 09.04.2025 00:30:58
Integer overflow in Qt 3.3 before 3.3.7, 4.1 before 4.1.5, and 4.2 before 4.2.1, as used in the KDE khtml library, kdelibs 3.1.3, and possibly other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary...
- EPSS 1.53%
- Published 27.08.2003 04:00:00
- Last modified 03.04.2025 01:03:51
KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.