Unrated severityNVD Advisory· Published May 17, 2010· Updated Apr 29, 2026
CVE-2010-1000
CVE-2010-1000
Description
Directory traversal vulnerability in KGet in KDE SC 4.0.0 through 4.4.3 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.
Affected products
53cpe:2.3:a:kde:kde_sc:4.0.0:*:*:*:*:*:*:*+ 52 more
- cpe:2.3:a:kde:kde_sc:4.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.0.0:alpha1:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.0.0:alpha2:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.0.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.0.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.0.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.0.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.0.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.0.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.1.0:alpha1:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.1.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.1.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.1.0:rc:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.1.80:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.1.85:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.1.96:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.2:beta2:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.2:rc:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.3.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.3.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.3.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.3.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.3.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.3.4:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.3.5:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.4.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.4.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.4.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.4.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.4.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:kde:kde_sc:4.4.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
21- secunia.com/advisories/39528nvdVendor Advisory
- secunia.com/advisories/39787nvdVendor Advisory
- secunia.com/advisories/42423nvdVendor Advisory
- secunia.com/secunia_research/2010-69/nvdVendor Advisory
- www.kde.org/info/security/advisory-20100513-1.txtnvdVendor Advisory
- www.vupen.com/english/advisories/2010/1142nvdVendor Advisory
- www.vupen.com/english/advisories/2010/1144nvdVendor Advisory
- www.vupen.com/english/advisories/2010/3096nvdVendor Advisory
- lists.fedoraproject.org/pipermail/package-announce/2010-November/051692.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2011-April/058580.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.htmlnvd
- marc.infonvd
- osvdb.org/64690nvd
- securitytracker.com/idnvd
- www.mandriva.com/security/advisoriesnvd
- www.securityfocus.com/archive/1/511281/100/0/threadednvd
- www.securityfocus.com/archive/1/511294/100/0/threadednvd
- www.securityfocus.com/bid/40141nvd
- www.ubuntu.com/usn/USN-938-1nvd
- www.vupen.com/english/advisories/2011/1101nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/58628nvd
News mentions
0No linked articles in our index yet.