4.3
CVSSv2

CVE-2006-6660

Published: 20/12/2006 Updated: 08/03/2011
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 440
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The nodeType function in KDE libkhtml 4.2.0 and previous versions, as used by Konquerer, KMail, and other programs, allows remote malicious users to cause a denial of service (crash) via malformed HTML tags, possibly involving a COL SPAN tag embedded in a RANGE tag.

Vulnerable Product Search on Vulmon Subscribe to Product

kde libkhtml

Exploits

<!-- KDE 35 | libkhtml <= 420 / Unhandled HTML Parse Exception ============================================================ Tested with Konqueror 352 and kmail 191 Federico L Bossi Bonin fbossi@globalstcomar wwwglobalstcomar Program received signal SIGSEGV, Segmentation fault 0xb64d81ff in DOM::Node::nodeType () from /usr/kde ...
source: wwwsecurityfocuscom/bid/21662/info KDE libkhtml is prone to a denial-of-service vulnerability This issue is triggered when an attacker convinces a victim user to open a malicious HTML document via an affected application such as kmail or Konqueror Remote attackers may exploit this issue to crash applications that use the affe ...