Kdelibs

Vendor:

First CVE: Jan 10, 2005 · Active for 21 years

8
Total CVEs
More Total CVEs than 87% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Kdelibs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 10, 2005
21 years ago
Most Recent CVE
Jul 25, 2017
3,290 days ago

CVE Severity & Scoring

Kdelibs8 CVEs
All CVEs353,240 CVEs
MediumHigh
Attack Vector
Local3 (37.5%)
Network0 (0.0%)
Unknown5 (62.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (25.0%)
High1 (12.5%)
Unknown5 (62.5%)
User Interaction
None2 (25.0%)
Unknown5 (62.5%)
Required1 (12.5%)
Privileges Required
Low2 (25.0%)
High0 (0.0%)
None1 (12.5%)
Unknown5 (62.5%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.
May 17, 20177.838NOYES
Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the com
Jan 10, 20057.536NOYES
KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man
Sep 8, 20097.524NONO
KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions
Aug 19, 20146.923NONO
kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentia
Mar 2, 20175.521NONO
kioslave/http/http.cpp in KIO in kdelibs 4.10.3 and earlier allows attackers to discover credentials via a crafted request that triggers an "internal server error," which includes
Feb 5, 20145.020NONO
aRts 1.5.10 and kdelibs3 3.5.10 and earlier do not properly create temporary directories, which allows local users to hijack the IPC by pre-creating the temporary directory.
Jul 25, 20177.018NONO
kio/usernotificationhandler.cpp in the POP3 kioslave in kdelibs 4.10.95 before 4.13.3 does not properly generate warning notifications, which allows man-in-the-middle attackers to
Jul 1, 20144.314NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
25.0% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Kdelibs

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.317.51.3%00
4.2.417.51.3%00
4.13.9516.90.4%00
4.13.9016.90.4%00
4.13.8016.90.4%00
4.13.316.90.4%00
4.13.216.90.4%00
4.13.125.60.5%00
4.13.025.60.5%00
4.12.9725.60.5%00
4.12.9525.60.5%00
4.12.9025.60.5%00
4.12.8025.60.5%00
4.12.525.60.5%00
4.12.425.60.5%00
4.12.325.60.5%00
4.12.225.60.5%00
4.12.125.60.5%00
4.12.025.60.5%00
4.11.9725.60.5%00