VYPR

Vendor CVEs

KDE

All CVEs

226 total · sorted by risk
  • CVE-2025-32898MedDec 5, 2025
    risk 0.31cvss 4.7epss 0.00

    The KDE Connect verification-code protocol before 2025-04-18 uses only 8 characters and therefore allows brute-force attacks. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and…

  • CVE-2025-32900MedDec 5, 2025
    risk 0.28cvss 4.3epss 0.00

    In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a device, because broadcast UDP is used. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE…

  • CVE-2025-32901MedDec 5, 2025
    risk 0.28cvss 4.3epss 0.00

    In KDE Connect before 1.33.0 on Android, malicious device IDs (sent via broadcast UDP) could cause an application crash.

  • CVE-2025-32899MedDec 5, 2025
    risk 0.28cvss 4.3epss 0.00

    In KDE Connect before 1.33.0 on Android, a packet can be crafted that causes two paired devices to unpair. Specifically, it is an invalid discovery packet sent over broadcast UDP.

  • CVE-2019-10734MedApr 7, 2019
    risk 0.28cvss 4.3epss 0.01

    In KDE Trojita 0.7, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by…

  • CVE-2019-10732MedApr 7, 2019
    risk 0.28cvss 4.3epss 0.01

    In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by…

  • CVE-2026-42095MedApr 24, 2026
    risk 0.26cvss 4.0epss 0.00

    bookserver in KDE Arianna before 26.04.1 allows attackers to read files over a socket connection by guessing a URL.

  • CVE-2024-57966MedFeb 3, 2025
    risk 0.26cvss 5.0epss 0.00

    libarchiveplugin.cpp in KDE ark before 24.12.0 can extract to an absolute path from an archive.

  • CVE-2025-66270MedDec 5, 2025
    risk 0.24cvss 4.7epss 0.00

    The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect before 25.12 on desktop, KDE Connect before 0.5.4 on iOS, KDE Connect before 1.34.4 on Android, GSConnect before 68, and Valent before 1.0.0.alpha.49.

  • CVE-2021-38372LowAug 10, 2021
    risk 0.24cvss 3.7epss 0.01

    In KDE Trojita 0.7, man-in-the-middle attackers can create new folders because untagged responses from an IMAP server are accepted before STARTTLS.

  • CVE-2025-69412LowJan 1, 2026
    risk 0.22cvss 3.4epss 0.00

    KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.

  • CVE-2020-16116LowAug 3, 2020
    risk 0.22cvss 3.3epss 0.02

    In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.

  • CVE-2020-12755LowMay 9, 2020
    risk 0.21cvss 3.3epss 0.00

    fishProtocol::establishConnection in fish/fish.cpp in KDE kio-extras through 20.04.0 makes a cacheAuthentication call even if the user had not set the keepPassword option. This may lead to unintended KWallet storage of a password.

  • CVE-2025-55174LowNov 26, 2025
    risk 0.14cvss 3.2epss 0.00

    In KDE Skanpage before 25.08.0, an attempt at file overwrite can result in the contents of the new file at the beginning followed by the partial contents of the old file at the end, because of use of QIODevice::ReadWrite instead of QODevice::WriteOnly.

  • CVE-2012-3456Aug 20, 2012
    risk 0.05cvss —epss 0.20

    Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in Calligra 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted…

  • CVE-2012-4515Nov 11, 2012
    risk 0.04cvss —epss 0.06

    Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by accessing an iframe when it is being updated.

  • CVE-2012-4514Nov 11, 2012
    risk 0.04cvss —epss 0.10

    rendering/render_replaced.cpp in Konqueror in KDE before 4.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted web page, related to "trying to reuse a frame with a null part."

  • CVE-2012-4513Nov 11, 2012
    risk 0.04cvss —epss 0.13

    khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via large canvas dimensions, which leads to an unexpected sign extension and a heap-based buffer over-read.

  • CVE-2008-4514Oct 9, 2008
    risk 0.04cvss —epss 0.08

    The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via a font tag with a long color value, which triggers an assertion error.

  • CVE-2007-1308Mar 7, 2007
    risk 0.04cvss —epss 0.08

    ecma/kjs_html.cpp in KDE JavaScript (KJS), as used in Konqueror in KDE 3.5.5, allows remote attackers to cause a denial of service (crash) by accessing the content of an iframe with an ftp:// URI in the src attribute, probably due to a NULL pointer dereference.

  • CVE-2006-3672Jul 18, 2006
    risk 0.04cvss —epss 0.07

    KDE Konqueror 3.5.1 and earlier allows remote attackers to cause a denial of service (application crash) by calling the replaceChild method on a DOM object, which triggers a null dereference, as demonstrated by calling document.replaceChild with a 0 (zero) argument.

  • CVE-2004-1491Dec 31, 2004
    risk 0.04cvss —epss 0.13

    Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code via a shortcut or launcher that contains an Exec entry.

  • CVE-2002-1224Oct 28, 2002
    risk 0.04cvss —epss 0.09

    Directory traversal vulnerability in kpf for KDE 3.0.1 through KDE 3.0.3a allows remote attackers to read arbitrary files as the kpf user via a URL with a modified icon parameter.

  • CVE-2000-0491May 24, 2000
    risk 0.04cvss —epss 0.18

    Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY request.

  • CVE-2009-2896Aug 20, 2009
    risk 0.03cvss —epss 0.06

    Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a subtitle (.srt) playlist file. NOTE: some of these details are obtained from third party information.

  • CVE-2008-5712Dec 24, 2008
    risk 0.03cvss —epss 0.04

    The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via (1) a long COLOR attribute in an HR element; or a long (a) BGCOLOR or (b) BORDERCOLOR attribute in a (2) TABLE, (3) TD, or (4) TR element. NOTE: the FONT vector…

  • CVE-2008-5698Dec 22, 2008
    risk 0.03cvss —epss 0.03

    HTMLTokenizer::scriptHandler in Konqueror in KDE 3.5.9 and 3.5.10 allows remote attackers to cause a denial of service (application crash) via an invalid document.load call that triggers use of a deleted object. NOTE: some of these details are obtained from third party…

  • CVE-2007-6000Nov 15, 2007
    risk 0.03cvss —epss 0.03

    KDE Konqueror 3.5.6 and earlier allows remote attackers to cause a denial of service (crash) via large HTTP cookie parameters.

  • CVE-2007-4941Sep 18, 2007
    risk 0.03cvss —epss 0.03

    KMPlayer 2.9.3.1210 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a .avi file with certain large "indx truck size" and nEntriesInuse values.

  • CVE-2007-4229Aug 8, 2007
    risk 0.03cvss —epss 0.02

    Unspecified vulnerability in KDE Konqueror 3.5.7 and earlier allows remote attackers to cause a denial of service (failed assertion and application crash) via certain malformed HTML, as demonstrated by a document containing TEXTAREA, BUTTON, BR, BDO, PRE, FRAMESET, and A tags. …

  • CVE-2007-1564Mar 21, 2007
    risk 0.03cvss —epss 0.04

    The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.

  • CVE-2006-7139Mar 7, 2007
    risk 0.03cvss —epss 0.03

    Kmail 1.9.1 on KDE 3.5.2, with "Prefer HTML to Plain Text" enabled, allows remote attackers to cause a denial of service (crash) via an HTML e-mail with certain table and frameset tags that trigger a segmentation fault, possibly involving invalid free or delete operations.

  • CVE-2006-6660Dec 20, 2006
    risk 0.03cvss —epss 0.03

    The nodeType function in KDE libkhtml 4.2.0 and earlier, as used by Konquerer, KMail, and other programs, allows remote attackers to cause a denial of service (crash) via malformed HTML tags, possibly involving a COL SPAN tag embedded in a RANGE tag.

  • CVE-2005-0404May 2, 2005
    risk 0.03cvss —epss 0.03

    KMail 1.7.1 in KDE 3.3.2 allows remote attackers to spoof email information, such as whether the email has been digitally signed or encrypted, via HTML formatted email.

  • CVE-2004-1165Jan 10, 2005
    risk 0.03cvss —epss 0.04

    Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.

  • CVE-2004-0527Aug 6, 2004
    risk 0.03cvss —epss 0.06

    KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing"…

  • CVE-2003-1478Dec 31, 2003
    risk 0.03cvss —epss 0.04

    Konqueror in KDE 3.0.3 allows remote attackers to cause a denial of service (core dump) via a web page that begins with a "xFFxFE" byte sequence and a large number of CRLF sequences, as demonstrated using freeze.htm.

  • CVE-2002-0227May 16, 2002
    risk 0.03cvss —epss 0.03

    KICQ 2.0.0b1 allows remote attackers to cause a denial of service (crash) via a malformed message.

  • CVE-2001-0782Oct 18, 2001
    risk 0.03cvss —epss 0.01

    KDE ktvision 0.1.1-271 and earlier allows local attackers to gain root privileges via a symlink attack on a user configuration file.

  • CVE-2001-0610Aug 2, 2001
    risk 0.03cvss —epss 0.01

    kfm as included with KDE 1.x can allow a local attacker to gain additional privileges via a symlink attack in the kfm cache directory in /tmp.

  • CVE-2000-0530May 31, 2000
    risk 0.03cvss —epss 0.01

    The KApplication class in the KDE 1.1.2 configuration file management capability allows local users to overwrite arbitrary files.

  • CVE-2000-0460May 27, 2000
    risk 0.03cvss —epss 0.01

    Buffer overflow in KDE kdesud on Linux allows local uses to gain privileges via a long DISPLAY environmental variable.

  • CVE-2000-0393May 16, 2000
    risk 0.03cvss —epss 0.01

    The KDE kscd program does not drop privileges when executing a program specified in a user's SHELL environmental variable, which allows the user to gain privileges by specifying an alternate program to execute.

  • CVE-1999-0735Jan 4, 2000
    risk 0.03cvss —epss 0.01

    KDE K-Mail allows local users to gain privileges via a symlink attack in temporary user directories.

  • CVE-2005-2971Oct 20, 2005
    risk 0.01cvss —epss 0.06

    Heap-based buffer overflow in the KWord RTF importer for KOffice 1.2.0 through 1.4.1 allows remote attackers to execute arbitrary code via a crafted RTF file.

  • CVE-2004-0888Jan 27, 2005
    risk 0.01cvss —epss 0.10

    Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by…

  • CVE-2004-1125Jan 10, 2005
    risk 0.01cvss —epss 0.07

    Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary…

  • CVE-2004-0867Dec 23, 2004
    risk 0.01cvss —epss 0.17

    Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session. NOTE: it was later reported that 2.x is…

  • CVE-2004-0803Dec 23, 2004
    risk 0.01cvss —epss 0.08

    Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files.

  • CVE-2004-0866Sep 16, 2004
    risk 0.01cvss —epss 0.10

    Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.

Page 2 of 5