📦

konqueror

Vendor: kde

Actively Exploited 0 CISA KEV List
PoC / Exploits 11 Code Available
Total RCEs 1 Remote Access
Total CVEs 35 Total Indexed
Avg. EPSS 3.41% Exploit Prob.
Latest CVE CVE-2009-4976 Aug 02

Security Vulnerability Index

Page 1 / 4
4.3 CVSS

Cross-site scripting (XSS) vulnerability in webkitpart.cpp in kwebkitpart allows remote attackers to inject arbitrary web script or HTML via a URL associated with a nonexistent domain name, related to a "universal XSS" issue, a similar vulnerability to CVE-2010-2536.

EPSS: 0.25%
4.3 CVSS

KDE Konqueror allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.

EPSS: 3.61%
5.0 CVSS
CVE-2008-5712
Exploit Found

The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via (1) a long COLOR attribute in an HR element; or a long (a) BGCOLOR or (b) BORDERCOLOR attribute in a (2) TABLE, (3) TD, or (4) TR element. NOTE: the FONT vector is already covered by CVE-2008-4514.

EPSS: 4.52%
4.3 CVSS
CVE-2008-5698
Exploit Found

HTMLTokenizer::scriptHandler in Konqueror in KDE 3.5.9 and 3.5.10 allows remote attackers to cause a denial of service (application crash) via an invalid document.load call that triggers use of a deleted object. NOTE: some of these details are obtained from third party information.

EPSS: 7.75%
5.0 CVSS
CVE-2008-4514
Exploit Found

The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via a font tag with a long color value, which triggers an assertion error.

EPSS: 4.58%
5.0 CVSS

Konqueror in KDE 3.5.9 allows remote attackers to cause a denial of service (application crash) via Javascript that calls the alert function with a URL-encoded string of a large number of invalid characters.

EPSS: 0.47%
4.3 CVSS

KDE Konqueror 3.5.5 and 3.95.00, when a user accepts an SSL server certificate on the basis of the CN domain name in the DN field, regards the certificate as also accepted for all domain names in subjectAltName:dNSName fields, even though these fields cannot be examined in the product, which makes it easier for remote attackers to trick a user into accepting an invalid certificate for a spoofed web site.

EPSS: 0.29%
5.0 CVSS
CVE-2007-6000
Exploit Found

KDE Konqueror 3.5.6 and earlier allows remote attackers to cause a denial of service (crash) via large HTTP cookie parameters.

EPSS: 4.23%
4.3 CVSS
CVE-2007-4229
Exploit Found

Unspecified vulnerability in KDE Konqueror 3.5.7 and earlier allows remote attackers to cause a denial of service (failed assertion and application crash) via certain malformed HTML, as demonstrated by a document containing TEXTAREA, BUTTON, BR, BDO, PRE, FRAMESET, and A tags. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: 4.12%
4.3 CVSS

KDE Konqueror 3.5.7 allows remote attackers to spoof the URL address bar by calling setInterval with a small interval and changing the window.location property.

EPSS: 0.89%