VYPR

Kdeconnect

by KDE

CVEs (6)

  • CVE-2025-32898MedDec 5, 2025
    risk 0.31cvss 4.7epss 0.00

    The KDE Connect verification-code protocol before 2025-04-18 uses only 8 characters and therefore allows brute-force attacks. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and…

  • CVE-2025-32900MedDec 5, 2025
    risk 0.28cvss 4.3epss 0.00

    In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a device, because broadcast UDP is used. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE…

  • CVE-2025-32901MedDec 5, 2025
    risk 0.28cvss 4.3epss 0.00

    In KDE Connect before 1.33.0 on Android, malicious device IDs (sent via broadcast UDP) could cause an application crash.

  • CVE-2025-32899MedDec 5, 2025
    risk 0.28cvss 4.3epss 0.00

    In KDE Connect before 1.33.0 on Android, a packet can be crafted that causes two paired devices to unpair. Specifically, it is an invalid discovery packet sent over broadcast UDP.

  • CVE-2025-66270MedDec 5, 2025
    risk 0.24cvss 4.7epss 0.00

    The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect before 25.12 on desktop, KDE Connect before 0.5.4 on iOS, KDE Connect before 1.34.4 on Android, GSConnect before 68, and Valent before 1.0.0.alpha.49.

  • CVE-2020-26164Oct 7, 2020
    risk 0.00cvss epss 0.01

    In kdeconnect-kde (aka KDE Connect) before 20.08.2, an attacker on the local network could send crafted packets that trigger use of large amounts of CPU, memory, or network connection slots, aka a Denial of Service attack.