7.5
CVSSv2

CVE-2005-0754

Published: 22/04/2005 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote malicious users to execute arbitrary code.

Vulnerable Product Search on Vulmon Subscribe to Product

kde quanta 3.1

conectiva linux 10.0

conectiva linux 9.0

kde kde 3.2.1

kde kde 3.2.2

ubuntu ubuntu linux 4.1

ubuntu ubuntu linux 5.04

kde kde 3.2.3

kde kde 3.3

gentoo linux

kde kde 3.2

redhat fedora core core_3.0

kde kde 3.3.1

kde kde 3.3.2

kde kde 3.4

Vendor Advisories

Eckhart W�rner discovered that Kommander opens files from remote and possibly untrusted locations without user confirmation Since Kommander files can contain scripts, this would allow an attacker to execute arbitrary code with the privileges of the user opening the file ...