CVE-2004-0803
- EPSS 17.88%
- Veröffentlicht 23.12.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files.
CVE-2004-0746
- EPSS 1.5%
- Veröffentlicht 20.10.2004 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session...
CVE-2004-0690
- EPSS 0.11%
- Veröffentlicht 28.09.2004 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The DCOPServer in KDE 3.2.3 and earlier allows local users to gain unauthorized access via a symlink attack on DCOP files in the /tmp directory.
CVE-2004-0689
- EPSS 0.03%
- Veröffentlicht 28.09.2004 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.
CVE-2003-0988
- EPSS 7.32%
- Veröffentlicht 17.02.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows attackers to execute arbitrary code via a VCF file.
CVE-2003-0692
- EPSS 1.21%
- Veröffentlicht 06.10.2003 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
KDM in KDE 3.1.3 and earlier uses a weak session cookie generation algorithm that does not provide 128 bits of entropy, which allows attackers to guess session cookies via brute force methods and gain access to the user session.
- EPSS 2.08%
- Veröffentlicht 06.10.2003 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam...
CVE-2003-0370
- EPSS 0.94%
- Veröffentlicht 16.06.2003 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.
CVE-2003-0204
- EPSS 1.5%
- Veröffentlicht 05.05.2003 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF files, related to missing -dPARANOIDSAFER and -dSAFER arguments when using the kghostview Ghostscript viewer.
CVE-2002-1393
- EPSS 2.44%
- Veröffentlicht 17.01.2003 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple vulnerabilities in KDE 2 and KDE 3.x through 3.0.5 do not quote certain parameters that are inserted into a shell command, which could allow remote attackers to execute arbitrary commands via (1) URLs, (2) filenames, or (3) e-mail addresses.