Vulnerabilities
Vulnerable Software
Kde:  >> Kdelibs  >> 2.1.0  Security Vulnerabilities
aRts 1.5.10 and kdelibs3 3.5.10 and earlier do not properly create temporary directories, which allows local users to hijack the IPC by pre-creating the temporary directory.
CVSS Score
7.0
EPSS Score
0.001
Published
2017-07-25
KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.
CVSS Score
7.8
EPSS Score
0.004
Published
2017-05-17
kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.
CVSS Score
5.5
EPSS Score
0.003
Published
2017-03-02
KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."
CVSS Score
6.9
EPSS Score
0.0
Published
2014-08-19
kioslave/http/http.cpp in KIO in kdelibs 4.10.3 and earlier allows attackers to discover credentials via a crafted request that triggers an "internal server error," which includes the username and password in an error message.
CVSS Score
5.0
EPSS Score
0.015
Published
2014-02-05


Contact Us

Shodan ® - All rights reserved