7.5
CVSSv2

CVE-2002-1393

Published: 17/01/2003 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple vulnerabilities in KDE 2 and KDE 3.x up to and including 3.0.5 do not quote certain parameters that are inserted into a shell command, which could allow remote malicious users to execute arbitrary commands via (1) URLs, (2) filenames, or (3) e-mail addresses.

Vulnerable Product Search on Vulmon Subscribe to Product

kde kde 2.1

kde kde 2.1.1

kde kde 2.1.2

kde kde 3.0.3

kde kde 3.0.3a

kde kde 2.2

kde kde 2.2.1

kde kde 3.0.4

kde kde 3.0.5

kde kde 2.2.2

kde kde 3.0

kde kde 2.0

kde kde 2.0.1

kde kde 3.0.1

kde kde 3.0.2

Vendor Advisories

The KDE team discovered several vulnerabilities in the K Desktop Environment In some instances KDE fails to properly quote parameters of instructions passed to a command shell for execution These parameters may incorporate data such as URLs, filenames and e-mail addresses, and this data may be provided remotely to a victim in an e-mail, a webpage ...
The KDE team discovered several vulnerabilities in the K Desktop Environment In some instances KDE fails to properly quote parameters of instructions passed to a command shell for execution These parameters may incorporate data such as URLs, filenames and e-mail addresses, and this data may be provided remotely to a victim in an e-mail, a webpage ...
The KDE team discovered several vulnerabilities in the K Desktop Environment In some instances KDE fails to properly quote parameters of instructions passed to a command shell for execution These parameters may incorporate data such as URLs, filenames and e-mail addresses, and this data may be provided remotely to a victim in an e-mail, a webpage ...
The KDE team discovered several vulnerabilities in the K Desktop Environment In some instances KDE fails to properly quote parameters of instructions passed to a command shell for execution These parameters may incorporate data such as URLs, filenames and e-mail addresses, and this data may be provided remotely to a victim in an e-mail, a webpage ...
The KDE team discovered several vulnerabilities in the K Desktop Environment In some instances KDE fails to properly quote parameters of instructions passed to a command shell for execution These parameters may incorporate data such as URLs, filenames and e-mail addresses, and this data may be provided remotely to a victim in an e-mail, a webpage ...
The KDE team discovered several vulnerabilities in the K Desktop Environment In some instances KDE fails to properly quote parameters of instructions passed to a command shell for execution These parameters may incorporate data such as URLs, filenames and e-mail addresses, and this data may be provided remotely to a victim in an e-mail, a webpage ...
The KDE team discovered several vulnerabilities in the K Desktop Environment In some instances KDE fails to properly quote parameters of instructions passed to a command shell for execution These parameters may incorporate data such as URLs, filenames and e-mail addresses, and this data may be provided remotely to a victim in an e-mail, a webpage ...