4.3
CVSSv2

CVE-2007-4224

Published: 08/08/2007 Updated: 15/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

KDE Konqueror 3.5.7 allows remote malicious users to spoof the URL address bar by calling setInterval with a small interval and changing the window.location property.

Vulnerable Product Search on Vulmon Subscribe to Product

kde konqueror 3.5.7

Vendor Advisories

It was discovered that Konqueror could be tricked into displaying incorrect URLs Remote attackers could exploit this to increase their chances of tricking a user into visiting a phishing URL, which could lead to credential theft ...

References

CWE-59http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065101.htmlhttp://www.kde.org/info/security/advisory-20070816-1.txthttps://issues.rpath.com/browse/RPL-1615https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00022.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-October/msg00085.htmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:176http://www.redhat.com/support/errata/RHSA-2007-0905.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0909.htmlhttp://lists.opensuse.org/opensuse-security-announce/2007-10/msg00006.htmlhttp://www.ubuntu.com/usn/usn-502-1http://www.securityfocus.com/bid/25219http://securitytracker.com/id?1018579http://secunia.com/advisories/26351http://secunia.com/advisories/26612http://secunia.com/advisories/26690http://secunia.com/advisories/26720http://secunia.com/advisories/27089http://secunia.com/advisories/27106http://secunia.com/advisories/27108http://secunia.com/advisories/27090http://secunia.com/advisories/27096http://secunia.com/advisories/27271http://securityreason.com/securityalert/2982http://www.vupen.com/english/advisories/2007/2807https://exchange.xforce.ibmcloud.com/vulnerabilities/35828https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9879http://www.securityfocus.com/archive/1/475763/100/0/threadedhttp://www.securityfocus.com/archive/1/475731/100/0/threadedhttp://www.securityfocus.com/archive/1/475730/100/0/threadedhttp://www.securityfocus.com/archive/1/475689/100/0/threadedhttps://usn.ubuntu.com/502-1/https://nvd.nist.gov