KDE records
198 published records for vendor kde.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 37
- With a fix record
- 56.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-399 Resource Management Errors11
- CWE-20 Improper Input Validation8
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor7
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')7
- CWE-189 Numeric Errors5
The weakness classes this vendor ships most often: where to look.
CWEAll records
198 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2004-0888No exploit | Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attakde · koffice | Critical10.0 | — | 9.5% | Jan 27, 2005 |
42Plan | CVE-2004-0889No exploit | Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of servxpdf · xpdf | Critical10.0 | — | 6.2% | Jan 27, 2005 |
41Plan | CVE-2005-0011No exploit | Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Interkde · kde | Critical10.0 | — | 4.9% | May 2, 2005 |
41Plan | CVE-2005-3625No exploit | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial libextractor · libextractor · CWE-399 | Critical10.0 | — | 3.8% | Dec 31, 2005 |
41Plan | CVE-2003-0690No exploit | KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privilegkde · kde | Critical10.0 | — | 3.1% | Oct 6, 2003 |
40Plan | CVE-2009-3608No exploit | Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdfpoppler · poppler · CWE-189 | Critical9.3 | — | 10.2% | Oct 21, 2009 |
40Plan | CVE-2009-3604No exploit | The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does kde · kpdf · CWE-399 | Critical9.3 | — | 8.7% | Oct 21, 2009 |
40Plan | CVE-2009-3606No exploit | Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allowpoppler · poppler · CWE-189 | Critical9.3 | — | 8.6% | Oct 21, 2009 |
40Plan | CVE-2006-3742No exploit | The KDE PAM configuration shipped with Fedora Core 5 causes KDM passwords to be cached, which allows attackers to login without a password bkde · kdebase | Critical10.0 | — | 1.4% | Sep 6, 2006 |
39Monitor | CVE-2004-1125No exploit | Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3xpdf · xpdf · CWE-20 | Critical9.3 | — | 6.6% | Jan 10, 2005 |
39Monitor | CVE-2009-2896Proof of concept | Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitkde · kmplayer · CWE-119 | Critical9.3 | — | 5.6% | Aug 20, 2009 |
38Monitor | CVE-2012-4512Proof of concept | The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possiblykde · kde · CWE-843 | High8.8 | — | 11.7% | Feb 8, 2020 |
38Monitor | CVE-2008-1670No exploit | Heap-based buffer overflow in the progressive PNG Image loader (decoders/pngloader.cpp) in KHTML in KDE 4.0.x up to 4.0.3 allows remote attakde · kde · CWE-119 | Critical9.3 | — | 4.8% | Apr 28, 2008 |
38Monitor | CVE-2009-4035No exploit | The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and vekde · kdegraphics · CWE-94 | Critical9.3 | — | 3.8% | Dec 21, 2009 |
35Monitor | CVE-2004-0867No exploit | Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which cmozilla · firefox · CWE-264 | High7.5 | — | 17.2% | Dec 23, 2004 |
33Monitor | CVE-2004-0866No exploit | Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which ckde · konqueror | High7.5 | — | 10.1% | Sep 16, 2004 |
33Monitor | CVE-2019-7443No exploit | KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp.kde · kauth · CWE-20 | High8.1 | — | 2.4% | May 7, 2019 |
33Monitor | CVE-2016-7967No exploit | KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled.kde · kmail · CWE-94 | High8.1 | — | 1.9% | Dec 23, 2016 |
33Monitor | CVE-2013-2120No exploit | The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate pakde · paste applet · CWE-287 | High8.4 | — | 0.6% | Feb 11, 2020 |
33Monitor | CVE-2016-3100No exploit | kinit in KDE Frameworks before 5.23.0 uses weak permissions (644) for /tmp/xauth-xxx-_y, which allows local users to obtain X11 cookies of okde · kde frameworks · CWE-200 | High8.4 | — | 0.4% | Jul 13, 2016 |
32Monitor | CVE-2004-0803No exploit | Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer ovlibtiff · libtiff | High7.5 | — | 8.3% | Dec 23, 2004 |
32Monitor | CVE-2004-0411No exploit | The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlokde · konqueror · CWE-88 | High7.5 | — | 7.8% | Jul 7, 2004 |
32Monitor | CVE-2005-2971No exploit | Heap-based buffer overflow in the KWord RTF importer for KOffice 1.2.0 through 1.4.1 allows remote attackers to execute arbitrary code via akde · koffice | High7.5 | — | 6.4% | Oct 20, 2005 |
32Monitor | CVE-2003-0988No exploit | Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows kde · kde | High7.5 | — | 6.2% | Feb 17, 2004 |
32Monitor | CVE-2006-0019No exploit | Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allokde · kde | High7.5 | — | 6.1% | Jan 20, 2006 |
- CVE-2004-088843Plan
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote atta
CriticalCVSS 10.0No exploitEPSS 10%kde · kofficeJan 27, 2005
- CVE-2004-088942Plan
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of serv
CriticalCVSS 10.0No exploitEPSS 6%xpdf · xpdfJan 27, 2005
- CVE-2005-001141Plan
Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Inter
CriticalCVSS 10.0No exploitEPSS 5%kde · kdeMay 2, 2005
- CVE-2005-362541Plan
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial
CriticalCVSS 10.0No exploitEPSS 4%libextractor · libextractorDec 31, 2005
- CVE-2003-069041Plan
KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileg
CriticalCVSS 10.0No exploitEPSS 3%kde · kdeOct 6, 2003
- CVE-2009-360840Plan
Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf
CriticalCVSS 9.3No exploitEPSS 10%poppler · popplerOct 21, 2009
- CVE-2009-360440Plan
The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does
CriticalCVSS 9.3No exploitEPSS 9%kde · kpdfOct 21, 2009
- CVE-2009-360640Plan
Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow
CriticalCVSS 9.3No exploitEPSS 9%poppler · popplerOct 21, 2009
- CVE-2006-374240Plan
The KDE PAM configuration shipped with Fedora Core 5 causes KDM passwords to be cached, which allows attackers to login without a password b
CriticalCVSS 10.0No exploitEPSS 1%kde · kdebaseSep 6, 2006
- CVE-2004-112539Monitor
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3
CriticalCVSS 9.3No exploitEPSS 7%xpdf · xpdfJan 10, 2005
- CVE-2009-289639Monitor
Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbit
CriticalCVSS 9.3Proof of conceptEPSS 6%kde · kmplayerAug 20, 2009
- CVE-2012-451238Monitor
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly
HighCVSS 8.8Proof of conceptEPSS 12%kde · kdeFeb 8, 2020
- CVE-2008-167038Monitor
Heap-based buffer overflow in the progressive PNG Image loader (decoders/pngloader.cpp) in KHTML in KDE 4.0.x up to 4.0.3 allows remote atta
CriticalCVSS 9.3No exploitEPSS 5%kde · kdeApr 28, 2008
- CVE-2009-403538Monitor
The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and ve
CriticalCVSS 9.3No exploitEPSS 4%kde · kdegraphicsDec 21, 2009
- CVE-2004-086735Monitor
Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which c
HighCVSS 7.5No exploitEPSS 17%mozilla · firefoxDec 23, 2004
- CVE-2004-086633Monitor
Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which c
HighCVSS 7.5No exploitEPSS 10%kde · konquerorSep 16, 2004
- CVE-2019-744333Monitor
KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp.
HighCVSS 8.1No exploitEPSS 2%kde · kauthMay 7, 2019
- CVE-2016-796733Monitor
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled.
HighCVSS 8.1No exploitEPSS 2%kde · kmailDec 23, 2016
- CVE-2013-212033Monitor
The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate pa
HighCVSS 8.4No exploitEPSS 1%kde · paste appletFeb 11, 2020
- CVE-2016-310033Monitor
kinit in KDE Frameworks before 5.23.0 uses weak permissions (644) for /tmp/xauth-xxx-_y, which allows local users to obtain X11 cookies of o
HighCVSS 8.4No exploitEPSS 0%kde · kde frameworksJul 13, 2016
- CVE-2004-080332Monitor
Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer ov
HighCVSS 7.5No exploitEPSS 8%libtiff · libtiffDec 23, 2004
- CVE-2004-041132Monitor
The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlo
HighCVSS 7.5No exploitEPSS 8%kde · konquerorJul 7, 2004
- CVE-2005-297132Monitor
Heap-based buffer overflow in the KWord RTF importer for KOffice 1.2.0 through 1.4.1 allows remote attackers to execute arbitrary code via a
HighCVSS 7.5No exploitEPSS 6%kde · kofficeOct 20, 2005
- CVE-2003-098832Monitor
Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows
HighCVSS 7.5No exploitEPSS 6%kde · kdeFeb 17, 2004
- CVE-2006-001932Monitor
Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allo
HighCVSS 7.5No exploitEPSS 6%kde · kdeJan 20, 2006