7.5
CVSSv2

CVE-2004-0411

Published: 07/07/2004 Updated: 13/02/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The URI handlers in Konqueror for KDE 3.2.2 and previous versions do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote malicious users to manipulate the options that are passed to the associated programs, possibly to read arbitrary files or execute arbitrary code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kde konqueror

Vendor Advisories

Synopsis kdelibs security update Type/Severity Security Advisory: Important Topic Updated kdelibs packages that fix telnet URI handler and mailto URI handlerfile vulnerabilities are now available Description The kdelibs packages include libraries for the K Desktop Environment KDE Librarie ...