CVE-2004-0803
- EPSS 17.88%
- Published 23.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files.
CVE-2004-0746
- EPSS 1.5%
- Published 20.10.2004 04:00:00
- Last modified 03.04.2025 01:03:51
Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session...
CVE-2004-0690
- EPSS 0.11%
- Published 28.09.2004 04:00:00
- Last modified 03.04.2025 01:03:51
The DCOPServer in KDE 3.2.3 and earlier allows local users to gain unauthorized access via a symlink attack on DCOP files in the /tmp directory.
CVE-2004-0689
- EPSS 0.03%
- Published 28.09.2004 04:00:00
- Last modified 03.04.2025 01:03:51
KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.
CVE-2003-0988
- EPSS 7.32%
- Published 17.02.2004 05:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows attackers to execute arbitrary code via a VCF file.
CVE-2003-0692
- EPSS 1.21%
- Published 06.10.2003 04:00:00
- Last modified 03.04.2025 01:03:51
KDM in KDE 3.1.3 and earlier uses a weak session cookie generation algorithm that does not provide 128 bits of entropy, which allows attackers to guess session cookies via brute force methods and gain access to the user session.
- EPSS 2.08%
- Published 06.10.2003 04:00:00
- Last modified 03.04.2025 01:03:51
KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam...
CVE-2003-0370
- EPSS 0.94%
- Published 16.06.2003 04:00:00
- Last modified 03.04.2025 01:03:51
Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.
CVE-2003-0204
- EPSS 1.5%
- Published 05.05.2003 04:00:00
- Last modified 03.04.2025 01:03:51
KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF files, related to missing -dPARANOIDSAFER and -dSAFER arguments when using the kghostview Ghostscript viewer.
CVE-2002-1393
- EPSS 2.44%
- Published 17.01.2003 05:00:00
- Last modified 03.04.2025 01:03:51
Multiple vulnerabilities in KDE 2 and KDE 3.x through 3.0.5 do not quote certain parameters that are inserted into a shell command, which could allow remote attackers to execute arbitrary commands via (1) URLs, (2) filenames, or (3) e-mail addresses.