2.6
CVSSv2

CVE-2006-3672

Published: 18/07/2006 Updated: 20/07/2017
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 265
Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P

Vulnerability Summary

KDE Konqueror 3.5.1 and previous versions allows remote malicious users to cause a denial of service (application crash) by calling the replaceChild method on a DOM object, which triggers a null dereference, as demonstrated by calling document.replaceChild with a 0 (zero) argument.

Vulnerable Product Search on Vulmon Subscribe to Product

kde konqueror 3.0.2

kde konqueror 3.0.3

kde konqueror 3.1.5

kde konqueror 3.2.1

kde konqueror

kde konqueror 2.1.1

kde konqueror 2.1.2

kde konqueror 3.0.5

kde konqueror 3.0.5b

kde konqueror 3.2.2

kde konqueror 3.2.2.6

kde konqueror 3.0

kde konqueror 3.0.1

kde konqueror 3.1.3

kde konqueror 3.1.4

kde konqueror 3.3.1

kde konqueror 3.3.2

kde konqueror 2.2.1

kde konqueror 2.2.2

kde konqueror 3.1

kde konqueror 3.1.1

kde konqueror 3.1.2

kde konqueror 3.2.3

kde konqueror 3.3

Vendor Advisories

A Denial of Service vulnerability has been reported in the replaceChild() method in KDE’s DOM handler A malicious remote web page could exploit this to cause Konqueror to crash ...

Exploits

source: wwwsecurityfocuscom/bid/18978/info KDE Konqueror is prone to a denial-of-service vulnerability This issue is triggered when an attacker convinces a victim user to visit a malicious website Remote attackers may exploit this issue to crash Konqueror, effectively denying service to legitimate users documentreplaceChild(0); ...