Page 5 of 53 results (0.004 seconds)

CVSS: 7.5EPSS: 2%CPEs: 8EXPL: 1

24 Sep 2002 — The SSL capability for Konqueror in KDE 3.0.2 and earlier does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack. La capacidad SSL en Konqueror 3.0.2 y anteriores no verifica las restriccíones básicas de una certificad intermedio firmado por una AC (Autoridad Certificadora), lo que permite a atacantes remotos falsear los certificados de sitios de confianza mediante un ataque de h... • ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-047.0.txt •

CVSS: 7.5EPSS: 2%CPEs: 2EXPL: 1

03 May 2002 — KICQ 2.0.0b1 allows remote attackers to cause a denial of service (crash) via a malformed message. KICQ 2.0.0b1 permite a atacantes remotos causar una denegación de servicio (caída) mediante un mensaje malformado. • https://www.exploit-db.com/exploits/21262 •

CVSS: 7.8EPSS: 0%CPEs: 5EXPL: 1

27 Jul 2001 — kfm as included with KDE 1.x can allow a local attacker to gain additional privileges via a symlink attack in the kfm cache directory in /tmp. • https://www.exploit-db.com/exploits/20781 •

CVSS: 7.2EPSS: 0%CPEs: 2EXPL: 5

31 May 2000 — The KApplication class in the KDE 1.1.2 configuration file management capability allows local users to overwrite arbitrary files. • https://www.exploit-db.com/exploits/19979 •

CVSS: 7.8EPSS: 0%CPEs: 4EXPL: 2

27 May 2000 — Buffer overflow in KDE kdesud on Linux allows local uses to gain privileges via a long DISPLAY environmental variable. • https://www.exploit-db.com/exploits/19970 •

CVSS: 8.8EPSS: 0%CPEs: 4EXPL: 1

16 May 2000 — The KDE kscd program does not drop privileges when executing a program specified in a user's SHELL environmental variable, which allows the user to gain privileges by specifying an alternate program to execute. • https://www.exploit-db.com/exploits/19915 •

CVSS: 5.5EPSS: 0%CPEs: 2EXPL: 1

01 Mar 1999 — The libmediatool library used for the KDE mediatool allows local users to create arbitrary files via a symlink attack. La librería libmediatool usada para el mediatool de KDE permite a usuarios locales crear ficheros arbitrarios mediante un ataque de enlaces simbólicos (symlink attack) • ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-1999-005.0.txt •

CVSS: 7.1EPSS: 0%CPEs: 3EXPL: 0

18 Nov 1998 — KDE klock allows local users to kill arbitrary processes by specifying an arbitrary PID in the .kss.pid file. • http://marc.info/?l=bugtraq&m=91141486301691&w=2 •

CVSS: 7.8EPSS: 0%CPEs: 3EXPL: 0

18 Nov 1998 — KDE allows local users to execute arbitrary commands by setting the KDEDIR environmental variable to modify the search path that KDE uses to locate its executables. • http://marc.info/?l=bugtraq&m=91141486301691&w=2 •

CVSS: 7.1EPSS: 0%CPEs: 3EXPL: 0

18 Nov 1998 — KDE kppp allows local users to create a directory in an arbitrary location via the HOME environmental variable. • http://marc.info/?l=bugtraq&m=91141486301691&w=2 •