Vulnerabilities
Vulnerable Software
Kde:  >> Kdelibs  >> 4.14  Security Vulnerabilities
KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.
CVSS Score
7.8
EPSS Score
0.004
Published
2017-05-17
kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.
CVSS Score
5.5
EPSS Score
0.003
Published
2017-03-02


Contact Us

Shodan ® - All rights reserved