CVE-2004-1158
- EPSS 3.86%
- Published 10.01.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window or tab whose name is known but resides in a different domain, as demonstrated usi...
CVE-2004-0867
- EPSS 3.64%
- Published 23.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session. NOTE: it w...
CVE-2004-0746
- EPSS 1.5%
- Published 20.10.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session...
- EPSS 0.82%
- Published 16.09.2004 04:00:00
- Last modified 03.04.2025 01:03:51
KDE Konqueror does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, a...
CVE-2004-0866
- EPSS 3.54%
- Published 16.09.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.
- EPSS 2.83%
- Published 06.08.2004 04:00:00
- Last modified 03.04.2025 01:03:51
KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which ...
CVE-2004-0721
- EPSS 0.79%
- Published 27.07.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Konqueror 3.1.3, 3.2.2, and possibly other versions does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vul...
CVE-2004-0411
- EPSS 6.49%
- Published 07.07.2004 04:00:00
- Last modified 03.04.2025 01:03:51
The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attackers to manipulate the options that are passed to th...
CVE-2003-0592
- EPSS 0.83%
- Published 15.04.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie o...
CVE-2003-1478
- EPSS 2.17%
- Published 31.12.2003 05:00:00
- Last modified 03.04.2025 01:03:51
Konqueror in KDE 3.0.3 allows remote attackers to cause a denial of service (core dump) via a web page that begins with a "xFFxFE" byte sequence and a large number of CRLF sequences, as demonstrated using freeze.htm.