6.8
CVSSv2

CVE-2012-4515

Published: 11/11/2012 Updated: 12/11/2012
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code by accessing an iframe when it is being updated.

Vulnerable Product Search on Vulmon Subscribe to Product

kde kde 4.7.3

Exploits

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Nth Dimension Security Advisory (NDSA20121010) Date: 10th October 2012 Author: Tim Brown <mailto:timb@nth-dimensionorguk> URL: <wwwnth-dimensionorguk/> / <wwwmachineorguk/> Product: Konqueror 473 <konquerorkdeorg/> Vendor: KDE <wwwkd ...
Konqueror version 473 suffers from a number of memory corruption vulnerabilities ...