Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Kde

First CVE: May 5, 1997Active for: 29 yearsTotal CVEs: 200
40.2
VTI Score
Medium

KDE's vulnerability footprint spans a well-represented portfolio of desktop environments, applications, and components that serve both individual users and enterprise deployments, with exposure that recurs across the core KDE framework, the Konqueror browser, KPDF viewer, the KDE Sc suite, and mail client applications. The vulnerability surface reflects the inherent challenges of parsing and handling user-supplied input across graphical and document-processing layers, with recurring weakness classes including improper input validation, path traversal, and exposure of sensitive information. While the vendor's disclosures frequently acquire public exploit code, the structural risk profile is defined by the breadth of the affected application ecosystem and the input-handling demands of a large, modular desktop framework rather than by critical-severity outcomes or confirmed mass exploitation. Defenders should prioritize KDE component updates as part of systematic desktop and application patching, particularly for exposed services and document-handling workflows; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
200
Total CVEs
More Total CVEs than 100% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Kde over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 5, 1997
29 years ago
Most Recent CVE
Apr 28, 2026
88 days ago

Products(56 total)

Top CVEs

Signals from CVEs in this vendor scope (200 CVEs).

200 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-4512HIGH
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face sou
Feb 8, 20208.843NOYES
CVE-2017-8422HIGH
KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.
May 17, 20177.838NOYES
CVE-2009-2896HIGH
Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a subtitl
Aug 20, 20099.338NOYES
CVE-2004-1165HIGH
Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the com
Jan 10, 20057.536NOYES
CVE-2012-4513MEDIUM
khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via large canvas dimensions, which l
Nov 11, 20126.435NOYES
CVE-2004-0888HIGH
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (cras
Jan 27, 200510.034NONO
CVE-2004-0889HIGH
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitra
Jan 27, 200510.033NONO
CVE-2004-1491MEDIUM
Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code via a shortcut or launcher that contains an Exec en
Dec 31, 20045.033NOYES
CVE-2012-4515MEDIUM
Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, allows remote attackers to cause a denial of service
Nov 11, 20126.832NOYES
CVE-2009-3608HIGH
Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and te
Oct 21, 20099.332NONO
View all 200 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products200 CVEs
9%
49%
43%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local26 (13.0%)
Network24 (12.0%)
Unknown145 (72.5%)
Physical2 (1.0%)
Adjacent Network3 (1.5%)
Attack Complexity
Low47 (23.5%)
High8 (4.0%)
Unknown145 (72.5%)
User Interaction
None38 (19.0%)
Unknown145 (72.5%)
Required17 (8.5%)
Privileges Required
Low14 (7.0%)
High1 (0.5%)
None40 (20.0%)
Unknown145 (72.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (200 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
31 CVEs
15.5% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Kde.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Kde — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Kde's Products

View all 4 CNAs →

Top CWEs