Home/Product/kde
Product

kde

136 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-36041
< 5.27.11.1
KSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6.x before 6.0.5.1 allows connections via ICE based
7.8HIGH
CVE-2024-1433
<= 5.93.0
A vulnerability, which was classified as problematic, was found in KDE Plasma Workspace up to 5.93.0. This affects the function Ev
3.1LOW
CVE-2021-38373
all versions
In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requir
5.3MEDIUM
CVE-2020-15954
all versions
KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in
6.5MEDIUM
CVE-2020-11880
< 19.12.3
An issue was discovered in KDE KMail before 19.12.3. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a websi
6.5MEDIUM
CVE-2019-10732
all versions
In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multip
4.3MEDIUM
CVE-2017-17689
all versions
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exf
5.9MEDIUM
CVE-2018-6791
< 5.12.0
An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive tha
6.8MEDIUM
CVE-2018-6790
< 5.12.0
An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote att
5.3MEDIUM
CVE-2014-8878
all versions
KDE KMail does not encrypt attachments in emails when "automatic encryption" is enabled, which allows remote attackers to obtain s
5.9MEDIUM
CVE-2015-7543
<= 3.5.10
aRts 1.5.10 and kdelibs3 3.5.10 and earlier do not properly create temporary directories, which allows local users to hijack the I
7.0HIGH
CVE-2017-9604
<= 5.5.1
KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin
7.5HIGH
CVE-2017-8422
<= 4.14.31
KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a
7.8HIGH
CVE-2017-6410
<= 4.14.29
kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (po
5.5MEDIUM
CVE-2016-7968
<= 5.3.0
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for Ja
6.5MEDIUM
CVE-2016-7967
<= 5.3.0
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the
8.1HIGH
CVE-2016-7966
<= 4.4.0
Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to t
7.3HIGH
CVE-2016-2312
<= 5.4.3
Turning all screens off in Plasma-workspace and kscreenlocker while the lock screen is shown can result in the screen being unlock
6.8MEDIUM
CVE-2015-1308
<= 5.1
kde-workspace 4.2.0 and plasma-workspace before 5.1.95 allows remote attackers to obtain input events, and consequently obtain pas
CVE-2015-1307
<= 5.1
plasma-workspace before 5.1.95 allows remote attackers to obtain passwords via a Trojan horse Look and Feel package.
CVE-2014-5033
<= 4.13.97
KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows l
CVE-2014-3494
all versions
kio/usernotificationhandler.cpp in the POP3 kioslave in kdelibs 4.10.95 before 4.13.3 does not properly generate warning notificat
CVE-2013-2074
<= 4.10.3
kioslave/http/http.cpp in KIO in kdelibs 4.10.3 and earlier allows attackers to discover credentials via a crafted request that tr
CVE-2011-2725
<= 4.7.4
Directory traversal vulnerability in Ark 4.7.x and earlier allows remote attackers to delete and force the display of arbitrary fi
CVE-2013-4132
<= 4.10.5
KDE-Workspace 4.10.5 and earlier does not properly handle the return value of the glibc 2.17 crypt and pw_encrypt functions, which
CVE-2012-4515
all versions
Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, all
CVE-2012-4514
<= 4.9.2
rendering/render_replaced.cpp in Konqueror in KDE before 4.9.3 allows remote attackers to cause a denial of service (NULL pointer
CVE-2012-4513
all versions
khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibl
CVE-2012-3455
<= 2.3.3
Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in K
CVE-2011-3365
all versions
The KDE SSL Wrapper (KSSL) API in KDE SC 4.6.0 through 4.7.1, and possibly earlier versions, does not use a certain font when rend
CVE-2011-1586
<= 4.6.2
Directory traversal vulnerability in the KGetMetalink::File::isValidNameAttr function in ui/metalinkcreator/metalinker.cpp in KGet
CVE-2011-1168
all versions
Cross-site scripting (XSS) vulnerability in the KHTMLPart::htmlError function in khtml/khtml_part.cpp in Konqueror in KDE SC 4.4.0
CVE-2010-2575
all versions
Heap-based buffer overflow in the RLE decompression functionality in the TranscribePalmImageToJPEG function in generators/plucker/
CVE-2010-1511
all versions
KGet 2.4.2 in KDE SC 4.0.0 through 4.4.3 does not properly request download confirmation from the user, which makes it easier for
CVE-2010-1000
all versions
Directory traversal vulnerability in KGet in KDE SC 4.0.0 through 4.4.3 allows remote attackers to create arbitrary files via dire
CVE-2010-0436
all versions
Race condition in backend/ctrl.c in KDM in KDE Software Compilation (SC) 2.2.0 through 4.4.2 allows local users to change the perm
CVE-2010-0923
all versions
Race condition in workspace/krunner/lock/lockdlg.cc in the KRunner lock module in kdebase in KDE SC 4.4.0 allows physically proxim
CVE-2009-4035
all versions
The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other librar
CVE-2009-2702
all versions
KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name in the Subject Alternative Na
CVE-2009-2537
all versions
KDE Konqueror allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length p
CVE-2008-5712
all versions
The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via (1) a long COL
CVE-2008-5698
all versions
HTMLTokenizer::scriptHandler in Konqueror in KDE 3.5.9 and 3.5.10 allows remote attackers to cause a denial of service (applicatio
CVE-2008-4382
all versions
Konqueror in KDE 3.5.9 allows remote attackers to cause a denial of service (application crash) via Javascript that calls the aler
CVE-2008-1671
all versions
start_kdeinit in KDE 3.5.5 through 3.5.9, when installed setuid root, allows local users to cause a denial of service and possibly
CVE-2008-1670
all versions
Heap-based buffer overflow in the progressive PNG Image loader (decoders/pngloader.cpp) in KHTML in KDE 4.0.x up to 4.0.3 allows r
CVE-2007-6591
all versions
KDE Konqueror 3.5.5 and 3.95.00, when a user accepts an SSL server certificate on the basis of the CN domain name in the DN field,
CVE-2007-5963
all versions
Unspecified vulnerability in kdebase allows local users to cause a denial of service (KDM login inaccessible, or resource consumpt
CVE-2007-6000
<= 3.5.6
KDE Konqueror 3.5.6 and earlier allows remote attackers to cause a denial of service (crash) via large HTTP cookie parameters.
CVE-2007-4569
all versions
backend/session.c in KDM in KDE 3.3.0 through 3.5.7, when autologin is configured and "shutdown with password" is enabled, allows
CVE-2007-4229
<= 3.5.7
Unspecified vulnerability in KDE Konqueror 3.5.7 and earlier allows remote attackers to cause a denial of service (failed assertio
CVE-2007-4225
all versions
Visual truncation vulnerability in KDE Konqueror 3.5.7 allows remote attackers to spoof the URL address bar via an http URI with a
CVE-2007-4224
all versions
KDE Konqueror 3.5.7 allows remote attackers to spoof the URL address bar by calling setInterval with a small interval and changing
CVE-2007-3820
all versions
konqueror/konq_combo.cc in Konqueror 3.5.7 allows remote attackers to spoof the data: URI scheme in the address bar via a long URI
CVE-2007-3143
all versions
Visual truncation vulnerability in Konqueror 3.5.5 allows remote attackers to spoof the address bar and possibly conduct phishing
CVE-2007-2164
all versions
Konqueror 3.5.5 release 45.4 allows remote attackers to cause a denial of service (browser crash or abort) via JavaScript that mat
CVE-2007-1565
all versions
Konqueror 3.5.5 allows remote attackers to cause a denial of service (crash) by using JavaScript to read a child iframe having an
CVE-2007-1564
all versions
The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to connect to other servers, perform
CVE-2007-1308
all versions
ecma/kjs_html.cpp in KDE JavaScript (KJS), as used in Konqueror in KDE 3.5.5, allows remote attackers to cause a denial of service
CVE-2007-0537
all versions
The KDE HTML library (kdelibs), as used by Konqueror 3.5.5, does not properly parse HTML comments, which allows remote attackers t
CVE-2007-0104
all versions
The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 patch 2, (b) kpdf in KDE before 3.5.5, (c) poppler before 0.5.4,
CVE-2006-6120
all versions
Integer overflow in the KPresenter import filter for Microsoft PowerPoint files (filters/olefilters/lib/klaola.cc) in KOffice befo
CVE-2006-2933
all versions
kdesktop_lock in kdebase before 3.1.3-5.11 for KDE in Red Hat Enterprise Linux (RHEL) 3 does not properly terminate, which can pre
CVE-2006-3672
<= 3.5.1
KDE Konqueror 3.5.1 and earlier allows remote attackers to cause a denial of service (application crash) by calling the replaceChi
CVE-2006-2449
all versions
KDE Display Manager (KDM) in KDE 3.2.0 up to 3.5.3 allows local users to read arbitrary files via a symlink attack related to the
CVE-2006-0019
all versions
Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through
CVE-2005-4684
all versions
Konqueror can associate a cookie with multiple domains when the DNS resolver has a non-root domain in its search list, which allow
CVE-2005-3626
all versions
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause
CVE-2005-3625
all versions
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause
CVE-2005-3624
all versions
The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and
CVE-2005-2971
all versions
Heap-based buffer overflow in the KWord RTF importer for KOffice 1.2.0 through 1.4.1 allows remote attackers to execute arbitrary
CVE-2005-2494
all versions
kcheckpass in KDE 3.2.0 up to 3.4.2 allows local users to gain root access via a symlink attack on lock files.
CVE-2005-2101
all versions
langen2kvtml in KDE 3.0 to 3.4.2 creates insecure temporary files in /tmp with predictable names, which allows local users to over
CVE-2005-2097
all versions
xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk
CVE-2005-1920
>= 3.2 and <= 3.4.0
The (1) Kate and (2) Kwrite applications in KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup fil
7.5HIGH
CVE-2005-1852
all versions
Multiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, GNU Gadu, CenterICQ, Kadu, and
CVE-2005-1046
all versions
Buffer overflow in the kimgio library for KDE 3.4.0 allows remote attackers to execute arbitrary code via a crafted PCX image file
CVE-2005-0404
all versions
KMail 1.7.1 in KDE 3.3.2 allows remote attackers to spoof email information, such as whether the email has been digitally signed o
CVE-2005-0365
all versions
The dcopidlng script in KDE 3.2.x and 3.3.x creates temporary files with predictable filenames, which allows local users to overwr
CVE-2005-0237
all versions
The International Domain Name (IDN) support in Konqueror 3.2.1 on KDE 3.2.1 allows remote attackers to spoof domain names using pu
CVE-2005-0205
all versions
KPPP 2.1.2 in KDE 3.1.5 and earlier, when setuid root without certain wrappers, does not properly close a privileged file descript
CVE-2005-0078
all versions
The KDE screen saver in KDE before 3.0.5 does not properly check the return value from a certain function call, which allows attac
CVE-2005-0011
all versions
Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distrib
CVE-2005-0206
all versions
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certa
CVE-2005-0754
all versions
Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to ex
CVE-2004-0889
all versions
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a deni
CVE-2004-0888
all versions
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow r
CVE-2004-0886
all versions
Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corru
CVE-2004-1171
all versions
KDE 3.2.x and 3.3.0 through 3.3.2, when saving credentials that are (1) manually entered by the user or (2) created by the SMB pro
CVE-2004-1165
all versions
Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("
CVE-2004-1158
all versions
Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting conten
CVE-2004-1125
all versions
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpd
CVE-2004-1491
all versions
Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code v
CVE-2004-0867
all versions
Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.u
CVE-2004-0803
all versions
Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and
CVE-2004-0746
all versions
Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.u
CVE-2004-0690
all versions
The DCOPServer in KDE 3.2.3 and earlier allows local users to gain unauthorized access via a symlink attack on DCOP files in the /
CVE-2004-0689
< 3.3
KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to
7.1HIGH
CVE-2004-0870
all versions
KDE Konqueror does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (H
CVE-2004-0866
all versions
Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.u
CVE-2004-0527
all versions
KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "a
CVE-2004-0721
all versions
Konqueror 3.1.3, 3.2.2, and possibly other versions does not properly prevent a frame in one domain from injecting content into a
CVE-2004-0411
<= 3.2.2
The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telne
CVE-2003-0592
all versions
Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web applic
CVE-2003-0988
all versions
Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1
CVE-2003-1478
all versions
Konqueror in KDE 3.0.3 allows remote attackers to cause a denial of service (core dump) via a web page that begins with a "xFFxFE"
CVE-2003-0692
all versions
KDM in KDE 3.1.3 and earlier uses a weak session cookie generation algorithm that does not provide 128 bits of entropy, which allo
CVE-2003-0690
all versions
KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain roo
CVE-2003-0459
all versions
KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in t
CVE-2003-0370
<= 2.2.2
Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allo
CVE-2003-0204
all versions
KDE 2 and KDE 3.1.1 and earlier 3.x versions allows attackers to execute arbitrary commands via (1) PostScript (PS) or (2) PDF fil
CVE-2002-1393
all versions
Multiple vulnerabilities in KDE 2 and KDE 3.x through 3.0.5 do not quote certain parameters that are inserted into a shell command
CVE-2002-2333
all versions
Buffer overflow in konqueror in KDE 2.1 through 3.0 and 3.0.2 allows remote attackers to cause a denial of service (crash) via an
CVE-2002-1306
all versions
Multiple buffer overflows in LISa on KDE 2.x for 2.1 and later, and KDE 3.x before 3.0.4, allow (1) local and possibly remote atta
CVE-2002-1282
all versions
Unknown vulnerability in the telnet KIO subsystem (telnet.protocol) of KDE 2.x 2.1 and later allows local and remote attackers to
CVE-2002-1281
all versions
Unknown vulnerability in the rlogin KIO subsystem (rlogin.protocol) of KDE 2.x 2.1 and later, and KDE 3.x 3.0.4 and earlier, allow
CVE-2002-1247
all versions
Buffer overflow in LISa allows local users to gain access to a raw socket via a long LOGNAME environment variable for the resLISa
CVE-2002-1224
all versions
Directory traversal vulnerability in kpf for KDE 3.0.1 through KDE 3.0.3a allows remote attackers to read arbitrary files as the k
CVE-2002-1223
all versions
Buffer overflow in DSC 3.0 parser from GSview, as used in KGhostView in KDE 1.1 and KDE 3.0.3a, may allow attackers to cause a den
CVE-2002-1152
all versions
Konqueror in KDE 3.0 through 3.0.2 does not properly detect the "secure" flag in an HTTP cookie, which could cause Konqueror to se
CVE-2002-1151
all versions
The cross-site scripting protection for Konqueror in KDE 2.2.2 and 3.0 through 3.0.3 does not properly initialize the domains on s
CVE-2002-0970
all versions
The SSL capability for Konqueror in KDE 3.0.2 and earlier does not verify the Basic Constraints for an intermediate CA-signed cert
CVE-2002-0227
all versions
KICQ 2.0.0b1 allows remote attackers to cause a denial of service (crash) via a malformed message.
CVE-2001-0610
all versions
kfm as included with KDE 1.x can allow a local attacker to gain additional privileges via a symlink attack in the kfm cache direct
CVE-2000-0530
all versions
The KApplication class in the KDE 1.1.2 configuration file management capability allows local users to overwrite arbitrary files.
CVE-2000-0460
all versions
Buffer overflow in KDE kdesud on Linux allows local uses to gain privileges via a long DISPLAY environmental variable.
CVE-2000-0393
all versions
The KDE kscd program does not drop privileges when executing a program specified in a user's SHELL environmental variable, which a
CVE-2000-0371
all versions
The libmediatool library used for the KDE mediatool allows local users to create arbitrary files via a symlink attack.
CVE-1999-1268
all versions
Vulnerability in KDE konsole allows local users to hijack or observe sessions of other users by accessing certain devices.
CVE-1999-1107
all versions
Buffer overflow in kppp in KDE allows local users to gain root access via a long PATH environmental variable.
CVE-1999-0782
all versions
KDE kppp allows local users to create a directory in an arbitrary location via the HOME environmental variable.
CVE-1999-0781
all versions
KDE allows local users to execute arbitrary commands by setting the KDEDIR environmental variable to modify the search path that K
CVE-1999-0780
all versions
KDE klock allows local users to kill arbitrary processes by specifying an arbitrary PID in the .kss.pid file.
CVE-1999-1270
all versions
KMail in KDE 1.0 provides a PGP passphrase as a command line argument to other programs, which could allow local users to obtain t
CVE-1999-1096
all versions
Buffer overflow in kscreensaver in KDE klock allows local users to gain root privileges via a long HOME environmental variable.
CVE-1999-1106
all versions
Buffer overflow in kppp in KDE allows local users to gain root access via a long -c (account_name) command line argument.
CVE-1999-1267
all versions
KDE file manager (kfm) uses a TCP server for certain file operations, which allows remote attackers to modify arbitrary files by s
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin