Записи KDE
198 опубликованных записей вендора kde.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 37
- С записью об исправлении
- 56,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-399 Resource Management Errors11
- CWE-20 Improper Input Validation8
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor7
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')7
- CWE-189 Numeric Errors5
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
198 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
43В плане | CVE-2004-0888Эксплойта нет | Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attakde · koffice | Критическая10,0 | — | 9,5 % | 27 янв. 2005 г. |
42В плане | CVE-2004-0889Эксплойта нет | Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of servxpdf · xpdf | Критическая10,0 | — | 6,2 % | 27 янв. 2005 г. |
41В плане | CVE-2005-0011Эксплойта нет | Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Interkde · kde | Критическая10,0 | — | 4,9 % | 2 мая 2005 г. |
41В плане | CVE-2005-3625Эксплойта нет | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial libextractor · libextractor · CWE-399 | Критическая10,0 | — | 3,8 % | 31 дек. 2005 г. |
41В плане | CVE-2003-0690Эксплойта нет | KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privilegkde · kde | Критическая10,0 | — | 3,1 % | 6 окт. 2003 г. |
40В плане | CVE-2009-3608Эксплойта нет | Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdfpoppler · poppler · CWE-189 | Критическая9,3 | — | 10,2 % | 21 окт. 2009 г. |
40В плане | CVE-2009-3604Эксплойта нет | The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does kde · kpdf · CWE-399 | Критическая9,3 | — | 8,7 % | 21 окт. 2009 г. |
40В плане | CVE-2009-3606Эксплойта нет | Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allowpoppler · poppler · CWE-189 | Критическая9,3 | — | 8,6 % | 21 окт. 2009 г. |
40В плане | CVE-2006-3742Эксплойта нет | The KDE PAM configuration shipped with Fedora Core 5 causes KDM passwords to be cached, which allows attackers to login without a password bkde · kdebase | Критическая10,0 | — | 1,4 % | 6 сент. 2006 г. |
39Наблюдать | CVE-2004-1125Эксплойта нет | Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3xpdf · xpdf · CWE-20 | Критическая9,3 | — | 6,6 % | 10 янв. 2005 г. |
39Наблюдать | CVE-2009-2896Proof of concept | Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitkde · kmplayer · CWE-119 | Критическая9,3 | — | 5,6 % | 20 авг. 2009 г. |
38Наблюдать | CVE-2012-4512Proof of concept | The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possiblykde · kde · CWE-843 | Высокая8,8 | — | 11,7 % | 8 февр. 2020 г. |
38Наблюдать | CVE-2008-1670Эксплойта нет | Heap-based buffer overflow in the progressive PNG Image loader (decoders/pngloader.cpp) in KHTML in KDE 4.0.x up to 4.0.3 allows remote attakde · kde · CWE-119 | Критическая9,3 | — | 4,8 % | 28 апр. 2008 г. |
38Наблюдать | CVE-2009-4035Эксплойта нет | The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and vekde · kdegraphics · CWE-94 | Критическая9,3 | — | 3,8 % | 21 дек. 2009 г. |
35Наблюдать | CVE-2004-0867Эксплойта нет | Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which cmozilla · firefox · CWE-264 | Высокая7,5 | — | 17,2 % | 23 дек. 2004 г. |
33Наблюдать | CVE-2004-0866Эксплойта нет | Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which ckde · konqueror | Высокая7,5 | — | 10,1 % | 16 сент. 2004 г. |
33Наблюдать | CVE-2019-7443Эксплойта нет | KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp.kde · kauth · CWE-20 | Высокая8,1 | — | 2,4 % | 7 мая 2019 г. |
33Наблюдать | CVE-2016-7967Эксплойта нет | KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled.kde · kmail · CWE-94 | Высокая8,1 | — | 1,9 % | 23 дек. 2016 г. |
33Наблюдать | CVE-2013-2120Эксплойта нет | The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate pakde · paste applet · CWE-287 | Высокая8,4 | — | 0,6 % | 11 февр. 2020 г. |
33Наблюдать | CVE-2016-3100Эксплойта нет | kinit in KDE Frameworks before 5.23.0 uses weak permissions (644) for /tmp/xauth-xxx-_y, which allows local users to obtain X11 cookies of okde · kde frameworks · CWE-200 | Высокая8,4 | — | 0,4 % | 13 июл. 2016 г. |
32Наблюдать | CVE-2004-0803Эксплойта нет | Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer ovlibtiff · libtiff | Высокая7,5 | — | 8,3 % | 23 дек. 2004 г. |
32Наблюдать | CVE-2004-0411Эксплойта нет | The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlokde · konqueror · CWE-88 | Высокая7,5 | — | 7,8 % | 7 июл. 2004 г. |
32Наблюдать | CVE-2005-2971Эксплойта нет | Heap-based buffer overflow in the KWord RTF importer for KOffice 1.2.0 through 1.4.1 allows remote attackers to execute arbitrary code via akde · koffice | Высокая7,5 | — | 6,4 % | 20 окт. 2005 г. |
32Наблюдать | CVE-2003-0988Эксплойта нет | Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows kde · kde | Высокая7,5 | — | 6,2 % | 17 февр. 2004 г. |
32Наблюдать | CVE-2006-0019Эксплойта нет | Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allokde · kde | Высокая7,5 | — | 6,1 % | 20 янв. 2006 г. |
- CVE-2004-088843В плане
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote atta
КритическаяCVSS 10,0Эксплойта нетEPSS 10 %kde · koffice27 янв. 2005 г.
- CVE-2004-088942В плане
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of serv
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %xpdf · xpdf27 янв. 2005 г.
- CVE-2005-001141В плане
Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Inter
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %kde · kde2 мая 2005 г.
- CVE-2005-362541В плане
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %libextractor · libextractor31 дек. 2005 г.
- CVE-2003-069041В плане
KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileg
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %kde · kde6 окт. 2003 г.
- CVE-2009-360840В плане
Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf
КритическаяCVSS 9,3Эксплойта нетEPSS 10 %poppler · poppler21 окт. 2009 г.
- CVE-2009-360440В плане
The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does
КритическаяCVSS 9,3Эксплойта нетEPSS 9 %kde · kpdf21 окт. 2009 г.
- CVE-2009-360640В плане
Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow
КритическаяCVSS 9,3Эксплойта нетEPSS 9 %poppler · poppler21 окт. 2009 г.
- CVE-2006-374240В плане
The KDE PAM configuration shipped with Fedora Core 5 causes KDM passwords to be cached, which allows attackers to login without a password b
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %kde · kdebase6 сент. 2006 г.
- CVE-2004-112539Наблюдать
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3
КритическаяCVSS 9,3Эксплойта нетEPSS 7 %xpdf · xpdf10 янв. 2005 г.
- CVE-2009-289639Наблюдать
Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbit
КритическаяCVSS 9,3Proof of conceptEPSS 6 %kde · kmplayer20 авг. 2009 г.
- CVE-2012-451238Наблюдать
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly
ВысокаяCVSS 8,8Proof of conceptEPSS 12 %kde · kde8 февр. 2020 г.
- CVE-2008-167038Наблюдать
Heap-based buffer overflow in the progressive PNG Image loader (decoders/pngloader.cpp) in KHTML in KDE 4.0.x up to 4.0.3 allows remote atta
КритическаяCVSS 9,3Эксплойта нетEPSS 5 %kde · kde28 апр. 2008 г.
- CVE-2009-403538Наблюдать
The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and ve
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %kde · kdegraphics21 дек. 2009 г.
- CVE-2004-086735Наблюдать
Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which c
ВысокаяCVSS 7,5Эксплойта нетEPSS 17 %mozilla · firefox23 дек. 2004 г.
- CVE-2004-086633Наблюдать
Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which c
ВысокаяCVSS 7,5Эксплойта нетEPSS 10 %kde · konqueror16 сент. 2004 г.
- CVE-2019-744333Наблюдать
KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp.
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %kde · kauth7 мая 2019 г.
- CVE-2016-796733Наблюдать
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled.
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %kde · kmail23 дек. 2016 г.
- CVE-2013-212033Наблюдать
The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate pa
ВысокаяCVSS 8,4Эксплойта нетEPSS 1 %kde · paste applet11 февр. 2020 г.
- CVE-2016-310033Наблюдать
kinit in KDE Frameworks before 5.23.0 uses weak permissions (644) for /tmp/xauth-xxx-_y, which allows local users to obtain X11 cookies of o
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %kde · kde frameworks13 июл. 2016 г.
- CVE-2004-080332Наблюдать
Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer ov
ВысокаяCVSS 7,5Эксплойта нетEPSS 8 %libtiff · libtiff23 дек. 2004 г.
- CVE-2004-041132Наблюдать
The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlo
ВысокаяCVSS 7,5Эксплойта нетEPSS 8 %kde · konqueror7 июл. 2004 г.
- CVE-2005-297132Наблюдать
Heap-based buffer overflow in the KWord RTF importer for KOffice 1.2.0 through 1.4.1 allows remote attackers to execute arbitrary code via a
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %kde · koffice20 окт. 2005 г.
- CVE-2003-098832Наблюдать
Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %kde · kde17 февр. 2004 г.
- CVE-2006-001932Наблюдать
Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allo
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %kde · kde20 янв. 2006 г.