KDE's vulnerability footprint spans a well-represented portfolio of desktop environments, applications, and components that serve both individual users and enterprise deployments, with exposure that recurs across the core KDE framework, the Konqueror browser, KPDF viewer, the KDE Sc suite, and mail client applications. The vulnerability surface reflects the inherent challenges of parsing and handling user-supplied input across graphical and document-processing layers, with recurring weakness classes including improper input validation, path traversal, and exposure of sensitive information. While the vendor's disclosures frequently acquire public exploit code, the structural risk profile is defined by the breadth of the affected application ecosystem and the input-handling demands of a large, modular desktop framework rather than by critical-severity outcomes or confirmed mass exploitation. Defenders should prioritize KDE component updates as part of systematic desktop and application patching, particularly for exposed services and document-handling workflows; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kde over time
Signals from CVEs in this vendor scope (200 CVEs).
200 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4512HIGH The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face sou | Feb 8, 2020 | 8.8 | 43 | NO | YES |
CVE-2017-8422HIGH KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app. | May 17, 2017 | 7.8 | 38 | NO | YES |
CVE-2009-2896HIGH Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a subtitl | Aug 20, 2009 | 9.3 | 38 | NO | YES |
CVE-2004-1165HIGH Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the com | Jan 10, 2005 | 7.5 | 36 | NO | YES |
CVE-2012-4513MEDIUM khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via large canvas dimensions, which l | Nov 11, 2012 | 6.4 | 35 | NO | YES |
CVE-2004-0888HIGH Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (cras | Jan 27, 2005 | 10.0 | 34 | NO | NO |
CVE-2004-0889HIGH Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitra | Jan 27, 2005 | 10.0 | 33 | NO | NO |
CVE-2004-1491MEDIUM Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code via a shortcut or launcher that contains an Exec en | Dec 31, 2004 | 5.0 | 33 | NO | YES |
CVE-2012-4515MEDIUM Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, allows remote attackers to cause a denial of service | Nov 11, 2012 | 6.8 | 32 | NO | YES |
CVE-2009-3608HIGH Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and te | Oct 21, 2009 | 9.3 | 32 | NO | NO |
Signals from CVEs in this vendor scope (200 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kde.
Media articles that mention a CVE ID that affects a product developed by Kde — matched by CVE ID, not by vendor name.