CVE-2012-4513 describes a heap-based buffer over-read vulnerability in Konqueror (KDE 4.7.3) within the khtml/imload/scaledimageplane.h component. This flaw allows remote attackers to trigger a denial of service (crash) and potentially read memory by providing large canvas dimensions, leading to an unexpected sign extension. With a CVSS score of 6.4 (AV:N/AC:L/Au:N/C:P/I:N/A:P), it is considered a medium-severity vulnerability, indicating network-based exploitation with low complexity, resulting in partial confidentiality impact and partial availability impact. While not actively exploited in the wild and absent from the KEV catalog, an exploit (EDB-22406) is publicly available, though there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.7.3CPE matchmatch criteria | cpe:2.3:o:kde:kde:4.7.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.