Kde

Kde

65 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 6.39%
  • Published 20.01.2006 21:03:00
  • Last modified 03.04.2025 01:03:51

Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI.

  • EPSS 0.05%
  • Published 06.09.2005 23:03:00
  • Last modified 03.04.2025 01:03:51

kcheckpass in KDE 3.2.0 up to 3.4.2 allows local users to gain root access via a symlink attack on lock files.

  • EPSS 0.65%
  • Published 17.08.2005 04:00:00
  • Last modified 03.04.2025 01:03:51

langen2kvtml in KDE 3.0 to 3.4.2 creates insecure temporary files in /tmp with predictable names, which allows local users to overwrite arbitrary files.

  • EPSS 2.82%
  • Published 26.07.2005 04:00:00
  • Last modified 03.04.2025 01:03:51

The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive info...

  • EPSS 5.58%
  • Published 26.07.2005 04:00:00
  • Last modified 03.04.2025 01:03:51

Multiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, GNU Gadu, CenterICQ, Kadu, and other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an ...

  • EPSS 7.1%
  • Published 02.05.2005 04:00:00
  • Last modified 03.04.2025 01:03:51

Buffer overflow in the kimgio library for KDE 3.4.0 allows remote attackers to execute arbitrary code via a crafted PCX image file.

  • EPSS 4.91%
  • Published 02.05.2005 04:00:00
  • Last modified 03.04.2025 01:03:51

Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Interface (INDI) in KDE 3.3 to 3.3.2, allow local users and remote attackers to execute arbitrary code via stack-ba...

  • EPSS 0.08%
  • Published 02.05.2005 04:00:00
  • Last modified 03.04.2025 01:03:51

The KDE screen saver in KDE before 3.0.5 does not properly check the return value from a certain function call, which allows attackers with physical access to cause a crash and access the desktop session.

  • EPSS 0.08%
  • Published 02.05.2005 04:00:00
  • Last modified 03.04.2025 01:03:51

KPPP 2.1.2 in KDE 3.1.5 and earlier, when setuid root without certain wrappers, does not properly close a privileged file descriptor for a domain socket, which allows local users to read and write to /etc/hosts and /etc/resolv.conf and gain control o...

Exploit
  • EPSS 1.03%
  • Published 02.05.2005 04:00:00
  • Last modified 03.04.2025 01:03:51

The International Domain Name (IDN) support in Konqueror 3.2.1 on KDE 3.2.1 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from o...