Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
247 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.6% | 💥 Exploit | KDE Libkhtml | 20/12/2006 | 16/6/2026 | The nodeType function in KDE libkhtml 4.2.0 and earlier, as used by Konquerer, KMail, and other programs, allows remote attackers to cause a denial of service (crash) via malformed HTML tags, possibly involving a COL SPAN tag embedded in a RANGE tag. | |
| Modificada | Media (5) | 2.2% | — | Kdegraphics | 5/12/2006 | 16/6/2026 | Stack consumption vulnerability in the KFILE JPEG (kfile_jpeg) plugin in kdegraphics 3, as used by konqueror, digikam, and other KDE image browsers, allows remote attackers to cause a denial of service (stack consumption) via a crafted EXIF section in a JPEG file, which results in an infinite recursion. | |
| Modificada | Media (6.8) | 4.2% | — | KDE Koffice | 3/12/2006 | 16/6/2026 | Integer overflow in the KPresenter import filter for Microsoft PowerPoint files (filters/olefilters/lib/klaola.cc) in KOffice before 1.6.1 allows user-assisted remote attackers to execute arbitrary code via a crafted PPT file, which results in a heap-based buffer overflow. | |
| Modificada | Media (6.8) | 4.5% | — | QTRedhat Kdelibs | 18/10/2006 | 16/6/2026 | Integer overflow in Qt 3.3 before 3.3.7, 4.1 before 4.1.5, and 4.2 before 4.2.1, as used in the KDE khtml library, kdelibs 3.1.3, and possibly other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted pixmap image. | |
| Modificada | Alta (10) | 1.4% | — | Kdebase | 6/9/2006 | 16/6/2026 | The KDE PAM configuration shipped with Fedora Core 5 causes KDM passwords to be cached, which allows attackers to login without a password by attempting to log in multiple times. | |
| Modificada | Media (4.6) | 0.40% | — | KDERedhat Enterprise LinuxRedhat Enterprise Linux Desktop | 27/7/2006 | 16/6/2026 | kdesktop_lock in kdebase before 3.1.3-5.11 for KDE in Red Hat Enterprise Linux (RHEL) 3 does not properly terminate, which can prevent the screensaver from activating or prevent users from manually locking the desktop. | |
| Modificada | Baja (2.6) | 6.9% | 💥 Exploit | KDE Konqueror | 18/7/2006 | 16/6/2026 | KDE Konqueror 3.5.1 and earlier allows remote attackers to cause a denial of service (application crash) by calling the replaceChild method on a DOM object, which triggers a null dereference, as demonstrated by calling document.replaceChild with a 0 (zero) argument. | |
| Modificada | Media (4) | 0.38% | — | KDE | 15/6/2006 | 16/6/2026 | KDE Display Manager (KDM) in KDE 3.2.0 up to 3.5.3 allows local users to read arbitrary files via a symlink attack related to the session type for login. | |
| Modificada | Alta (7.8) | 0.39% | — | KDE Arts | 15/6/2006 | 16/6/2026 | artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping privileges. | |
| Modificada | Alta (7.5) | 6.1% | — | KDE | 20/1/2006 | 16/6/2026 | Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI. | |
| Modificada | Media (6.4) | 1.4% | — | KDE Konqueror | 31/12/2005 | 16/6/2026 | Konqueror can associate a cookie with multiple domains when the DNS resolver has a non-root domain in its search list, which allows remote attackers to trick a user into accepting a cookie for a hostname formed via search-list expansion of the hostname entered by the user, or steal a cookie for an expanded hostname,… | |
| Modificada | Media (5) | 2.3% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows. | |
| Modificada | Media (5) | 3.4% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference. | |
| Modificada | Alta (10) | 3.8% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins." | |
| Modificada | Alta (7.5) | 6.4% | — | KDE Koffice | 20/10/2005 | 16/6/2026 | Heap-based buffer overflow in the KWord RTF importer for KOffice 1.2.0 through 1.4.1 allows remote attackers to execute arbitrary code via a crafted RTF file. | |
| Modificada | Alta (7.2) | 0.44% | — | KDE | 6/9/2005 | 16/6/2026 | kcheckpass in KDE 3.2.0 up to 3.4.2 allows local users to gain root access via a symlink attack on lock files. | |
| Modificada | Media (5) | 1.3% | — | KDE | 17/8/2005 | 16/6/2026 | langen2kvtml in KDE 3.0 to 3.4.2 creates insecure temporary files in /tmp with predictable names, which allows local users to overwrite arbitrary files. | |
| Modificada | Baja (2.1) | 0.43% | — | KDE KpdfXpdf | 16/8/2005 | 16/6/2026 | xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf attempts to reconstruct the information. | |
| Modificada | Alta (7.5) | 4.7% | — | EKGKDECentericqKadu | 26/7/2005 | 16/6/2026 | Multiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, GNU Gadu, CenterICQ, Kadu, and other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an incoming message. | |
| Modificada | Alta (7.5) | 3.7% | — | KDEDebian Linux | 26/7/2005 | 16/6/2026 | The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information. | |
| Modificada | Alta (10) | 4.9% | — | KDE | 2/5/2005 | 16/6/2026 | Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Interface (INDI) in KDE 3.3 to 3.3.2, allow local users and remote attackers to execute arbitrary code via stack-based buffer overflows. | |
| Modificada | Media (5) | 3.0% | 💥 Exploit | KmailKDE | 2/5/2005 | 16/6/2026 | KMail 1.7.1 in KDE 3.3.2 allows remote attackers to spoof email information, such as whether the email has been digitally signed or encrypted, via HTML formatted email. | |
| Modificada | Baja (2.1) | 0.41% | — | KDE | 2/5/2005 | 16/6/2026 | The dcopidlng script in KDE 3.2.x and 3.3.x creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack. | |
| Modificada | Media (4.6) | 0.38% | — | Debian LinuxKDERedhat Enterprise LinuxRedhat Enterprise Linux Desktop+1 | 2/5/2005 | 16/6/2026 | The KDE screen saver in KDE before 3.0.5 does not properly check the return value from a certain function call, which allows attackers with physical access to cause a crash and access the desktop session. | |
| Modificada | Alta (7.5) | 5.4% | — | KDE | 2/5/2005 | 16/6/2026 | Buffer overflow in the kimgio library for KDE 3.4.0 allows remote attackers to execute arbitrary code via a crafted PCX image file. |