Kde

Konqueror Embedded

4 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.83%
  • Published 15.04.2004 04:00:00
  • Last modified 03.04.2025 01:03:51

Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie o...

  • EPSS 1.53%
  • Published 27.08.2003 04:00:00
  • Last modified 03.04.2025 01:03:51

KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.

  • EPSS 0.94%
  • Published 16.06.2003 04:00:00
  • Last modified 03.04.2025 01:03:51

Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.

  • EPSS 0.35%
  • Published 09.06.2003 04:00:00
  • Last modified 03.04.2025 01:03:51

Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates.