Kde

Kdelibs

8 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.1%
  • Published 25.07.2017 14:29:00
  • Last modified 20.04.2025 01:37:25

aRts 1.5.10 and kdelibs3 3.5.10 and earlier do not properly create temporary directories, which allows local users to hijack the IPC by pre-creating the temporary directory.

  • EPSS 0.37%
  • Published 17.05.2017 14:29:00
  • Last modified 20.04.2025 01:37:25

KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.

  • EPSS 0.29%
  • Published 02.03.2017 06:59:01
  • Last modified 20.04.2025 01:37:25

kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to ob...

Exploit
  • EPSS 0.03%
  • Published 19.08.2014 18:55:03
  • Last modified 12.04.2025 10:46:40

KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (...

Exploit
  • EPSS 0.18%
  • Published 01.07.2014 16:55:02
  • Last modified 12.04.2025 10:46:40

kio/usernotificationhandler.cpp in the POP3 kioslave in kdelibs 4.10.95 before 4.13.3 does not properly generate warning notifications, which allows man-in-the-middle attackers to obtain sensitive information via an invalid certificate.

  • EPSS 1.47%
  • Published 05.02.2014 19:55:28
  • Last modified 11.04.2025 00:51:21

kioslave/http/http.cpp in KIO in kdelibs 4.10.3 and earlier allows attackers to discover credentials via a crafted request that triggers an "internal server error," which includes the username and password in an error message.

  • EPSS 0.35%
  • Published 08.09.2009 18:30:00
  • Last modified 09.04.2025 00:30:58

KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted ...

  • EPSS 11.11%
  • Published 10.01.2005 05:00:00
  • Last modified 03.04.2025 01:03:51

Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated u...