KDE kayıtları
kde üreticisine ait 198 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 37
- Düzeltme kaydı olan
- %56,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-399 Resource Management Errors11
- CWE-20 Improper Input Validation8
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor7
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')7
- CWE-189 Numeric Errors5
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
198 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
43Planlayın | CVE-2004-0888İstismar yok | Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attakde · koffice | Kritik10,0 | — | %9,5 | 27 Oca 2005 |
42Planlayın | CVE-2004-0889İstismar yok | Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of servxpdf · xpdf | Kritik10,0 | — | %6,2 | 27 Oca 2005 |
41Planlayın | CVE-2005-0011İstismar yok | Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Interkde · kde | Kritik10,0 | — | %4,9 | 2 May 2005 |
41Planlayın | CVE-2005-3625İstismar yok | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial libextractor · libextractor · CWE-399 | Kritik10,0 | — | %3,8 | 31 Ara 2005 |
41Planlayın | CVE-2003-0690İstismar yok | KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privilegkde · kde | Kritik10,0 | — | %3,1 | 6 Eki 2003 |
40Planlayın | CVE-2009-3608İstismar yok | Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdfpoppler · poppler · CWE-189 | Kritik9,3 | — | %10,2 | 21 Eki 2009 |
40Planlayın | CVE-2009-3604İstismar yok | The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does kde · kpdf · CWE-399 | Kritik9,3 | — | %8,7 | 21 Eki 2009 |
40Planlayın | CVE-2009-3606İstismar yok | Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allowpoppler · poppler · CWE-189 | Kritik9,3 | — | %8,6 | 21 Eki 2009 |
40Planlayın | CVE-2006-3742İstismar yok | The KDE PAM configuration shipped with Fedora Core 5 causes KDM passwords to be cached, which allows attackers to login without a password bkde · kdebase | Kritik10,0 | — | %1,4 | 6 Eyl 2006 |
39İzleyin | CVE-2004-1125İstismar yok | Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3xpdf · xpdf · CWE-20 | Kritik9,3 | — | %6,6 | 10 Oca 2005 |
39İzleyin | CVE-2009-2896Kavram kanıtı | Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitkde · kmplayer · CWE-119 | Kritik9,3 | — | %5,6 | 20 Ağu 2009 |
38İzleyin | CVE-2012-4512Kavram kanıtı | The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possiblykde · kde · CWE-843 | Yüksek8,8 | — | %11,7 | 8 Şub 2020 |
38İzleyin | CVE-2008-1670İstismar yok | Heap-based buffer overflow in the progressive PNG Image loader (decoders/pngloader.cpp) in KHTML in KDE 4.0.x up to 4.0.3 allows remote attakde · kde · CWE-119 | Kritik9,3 | — | %4,8 | 28 Nis 2008 |
38İzleyin | CVE-2009-4035İstismar yok | The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and vekde · kdegraphics · CWE-94 | Kritik9,3 | — | %3,8 | 21 Ara 2009 |
35İzleyin | CVE-2004-0867İstismar yok | Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which cmozilla · firefox · CWE-264 | Yüksek7,5 | — | %17,2 | 23 Ara 2004 |
33İzleyin | CVE-2004-0866İstismar yok | Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which ckde · konqueror | Yüksek7,5 | — | %10,1 | 16 Eyl 2004 |
33İzleyin | CVE-2019-7443İstismar yok | KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp.kde · kauth · CWE-20 | Yüksek8,1 | — | %2,4 | 7 May 2019 |
33İzleyin | CVE-2016-7967İstismar yok | KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled.kde · kmail · CWE-94 | Yüksek8,1 | — | %1,9 | 23 Ara 2016 |
33İzleyin | CVE-2013-2120İstismar yok | The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate pakde · paste applet · CWE-287 | Yüksek8,4 | — | %0,6 | 11 Şub 2020 |
33İzleyin | CVE-2016-3100İstismar yok | kinit in KDE Frameworks before 5.23.0 uses weak permissions (644) for /tmp/xauth-xxx-_y, which allows local users to obtain X11 cookies of okde · kde frameworks · CWE-200 | Yüksek8,4 | — | %0,4 | 13 Tem 2016 |
32İzleyin | CVE-2004-0803İstismar yok | Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer ovlibtiff · libtiff | Yüksek7,5 | — | %8,3 | 23 Ara 2004 |
32İzleyin | CVE-2004-0411İstismar yok | The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlokde · konqueror · CWE-88 | Yüksek7,5 | — | %7,8 | 7 Tem 2004 |
32İzleyin | CVE-2005-2971İstismar yok | Heap-based buffer overflow in the KWord RTF importer for KOffice 1.2.0 through 1.4.1 allows remote attackers to execute arbitrary code via akde · koffice | Yüksek7,5 | — | %6,4 | 20 Eki 2005 |
32İzleyin | CVE-2003-0988İstismar yok | Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows kde · kde | Yüksek7,5 | — | %6,2 | 17 Şub 2004 |
32İzleyin | CVE-2006-0019İstismar yok | Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allokde · kde | Yüksek7,5 | — | %6,1 | 20 Oca 2006 |
- CVE-2004-088843Planlayın
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote atta
KritikCVSS 10,0İstismar yokEPSS %10kde · koffice27 Oca 2005
- CVE-2004-088942Planlayın
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of serv
KritikCVSS 10,0İstismar yokEPSS %6xpdf · xpdf27 Oca 2005
- CVE-2005-001141Planlayın
Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Inter
KritikCVSS 10,0İstismar yokEPSS %5kde · kde2 May 2005
- CVE-2005-362541Planlayın
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial
KritikCVSS 10,0İstismar yokEPSS %4libextractor · libextractor31 Ara 2005
- CVE-2003-069041Planlayın
KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileg
KritikCVSS 10,0İstismar yokEPSS %3kde · kde6 Eki 2003
- CVE-2009-360840Planlayın
Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf
KritikCVSS 9,3İstismar yokEPSS %10poppler · poppler21 Eki 2009
- CVE-2009-360440Planlayın
The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does
KritikCVSS 9,3İstismar yokEPSS %9kde · kpdf21 Eki 2009
- CVE-2009-360640Planlayın
Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow
KritikCVSS 9,3İstismar yokEPSS %9poppler · poppler21 Eki 2009
- CVE-2006-374240Planlayın
The KDE PAM configuration shipped with Fedora Core 5 causes KDM passwords to be cached, which allows attackers to login without a password b
KritikCVSS 10,0İstismar yokEPSS %1kde · kdebase6 Eyl 2006
- CVE-2004-112539İzleyin
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3
KritikCVSS 9,3İstismar yokEPSS %7xpdf · xpdf10 Oca 2005
- CVE-2009-289639İzleyin
Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbit
KritikCVSS 9,3Kavram kanıtıEPSS %6kde · kmplayer20 Ağu 2009
- CVE-2012-451238İzleyin
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly
YüksekCVSS 8,8Kavram kanıtıEPSS %12kde · kde8 Şub 2020
- CVE-2008-167038İzleyin
Heap-based buffer overflow in the progressive PNG Image loader (decoders/pngloader.cpp) in KHTML in KDE 4.0.x up to 4.0.3 allows remote atta
KritikCVSS 9,3İstismar yokEPSS %5kde · kde28 Nis 2008
- CVE-2009-403538İzleyin
The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and ve
KritikCVSS 9,3İstismar yokEPSS %4kde · kdegraphics21 Ara 2009
- CVE-2004-086735İzleyin
Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which c
YüksekCVSS 7,5İstismar yokEPSS %17mozilla · firefox23 Ara 2004
- CVE-2004-086633İzleyin
Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which c
YüksekCVSS 7,5İstismar yokEPSS %10kde · konqueror16 Eyl 2004
- CVE-2019-744333İzleyin
KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp.
YüksekCVSS 8,1İstismar yokEPSS %2kde · kauth7 May 2019
- CVE-2016-796733İzleyin
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled.
YüksekCVSS 8,1İstismar yokEPSS %2kde · kmail23 Ara 2016
- CVE-2013-212033İzleyin
The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate pa
YüksekCVSS 8,4İstismar yokEPSS %1kde · paste applet11 Şub 2020
- CVE-2016-310033İzleyin
kinit in KDE Frameworks before 5.23.0 uses weak permissions (644) for /tmp/xauth-xxx-_y, which allows local users to obtain X11 cookies of o
YüksekCVSS 8,4İstismar yokEPSS %0kde · kde frameworks13 Tem 2016
- CVE-2004-080332İzleyin
Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer ov
YüksekCVSS 7,5İstismar yokEPSS %8libtiff · libtiff23 Ara 2004
- CVE-2004-041132İzleyin
The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlo
YüksekCVSS 7,5İstismar yokEPSS %8kde · konqueror7 Tem 2004
- CVE-2005-297132İzleyin
Heap-based buffer overflow in the KWord RTF importer for KOffice 1.2.0 through 1.4.1 allows remote attackers to execute arbitrary code via a
YüksekCVSS 7,5İstismar yokEPSS %6kde · koffice20 Eki 2005
- CVE-2003-098832İzleyin
Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows
YüksekCVSS 7,5İstismar yokEPSS %6kde · kde17 Şub 2004
- CVE-2006-001932İzleyin
Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allo
YüksekCVSS 7,5İstismar yokEPSS %6kde · kde20 Oca 2006