Vulnerabilities
Vulnerable Software
Kde:  >> Kde  >> 1.2  Security Vulnerabilities
rendering/render_replaced.cpp in Konqueror in KDE before 4.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted web page, related to "trying to reuse a frame with a null part."
CVSS Score
5.0
EPSS Score
0.073
Published
2012-11-11
KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5 module.
CVSS Score
10.0
EPSS Score
0.021
Published
2003-10-06
KDM in KDE 3.1.3 and earlier uses a weak session cookie generation algorithm that does not provide 128 bits of entropy, which allows attackers to guess session cookies via brute force methods and gain access to the user session.
CVSS Score
7.5
EPSS Score
0.012
Published
2003-10-06
Buffer overflow in KDE kdesud on Linux allows local uses to gain privileges via a long DISPLAY environmental variable.
CVSS Score
7.2
EPSS Score
0.003
Published
2000-05-27
The KDE kscd program does not drop privileges when executing a program specified in a user's SHELL environmental variable, which allows the user to gain privileges by specifying an alternate program to execute.
CVSS Score
7.2
EPSS Score
0.003
Published
2000-05-16


Contact Us

Shodan ® - All rights reserved