7.5
CVSSv2

CVE-2006-0019

Published: 20/01/2006 Updated: 19/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 up to and including 3.5.0 allows remote malicious users to execute arbitrary code via a crafted, UTF-8 encoded URI.

Vulnerable Product Search on Vulmon Subscribe to Product

kde kde 3.2.0_beta1

kde kde 3.2.1

kde kde 3.3.2

kde kde 3.3.x

kde kde 3.2.x

kde kde 3.3

kde kde 3.4.1

kde kde 3.4.2

kde kde 3.2

kde kde 3.2.0

kde kde 3.3.0

kde kde 3.3.1

kde kde 3.5.0

kde kde 3.2.2

kde kde 3.2.3

kde kde 3.4

kde kde 3.4.0

Vendor Advisories

Maksim Orlovich discovered that kjs, the Javascript interpreter engine used by Konqueror and other parts of KDE, did not sufficiently verify the validity of UTF-8 encoded URIs Specially crafted URIs could trigger a buffer overflow By tricking an user into visiting a web site with malicious JavaScript code, a remote attacker could exploit this to ...
Maksim Orlovich discovered that the kjs Javascript interpreter, used in the Konqueror web browser and in other parts of KDE, performs insufficient bounds checking when parsing UTF-8 encoded Uniform Resource Identifiers, which may lead to a heap based buffer overflow and the execution of arbitrary code The old stable distribution (woody) is not aff ...