Konqueror
Vendor:
First CVE: Sep 24, 2002 · Active for 23 years
34
Total CVEs
More Total CVEs than 96% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
5.6
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Konqueror over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 24, 2002
23 years ago
Most Recent CVE
Aug 2, 2010
5,837 days ago
CVE Severity & Scoring
Konqueror34 CVEs
9%
59%
32%
All CVEs352,719 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown34 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown34 (100.0%)
User Interaction
None0 (0.0%)
Unknown34 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown34 (100.0%)
Top CVEs
Signals from CVEs in this product scope (34 CVEs).
34 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1165HIGH Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the com | Jan 10, 2005 | 7.5 | 36 | NO | YES |
CVE-2007-1564MEDIUM The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive informati | Mar 21, 2007 | 6.8 | 27 | NO | YES |
CVE-2004-0867HIGH Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a | Dec 23, 2004 | 7.5 | 26 | NO | NO |
CVE-2007-1308MEDIUM ecma/kjs_html.cpp in KDE JavaScript (KJS), as used in Konqueror in KDE 3.5.5, allows remote attackers to cause a denial of service (crash) by accessing the content of an iframe wit | Mar 7, 2007 | 4.3 | 25 | NO | YES |
CVE-2004-1158HIGH Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window or tab whos | Jan 10, 2005 | 7.5 | 25 | NO | NO |
CVE-2004-0411HIGH The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which a | Jul 7, 2004 | 7.5 | 25 | NO | NO |
CVE-2004-0866HIGH Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a | Sep 16, 2004 | 7.5 | 24 | NO | NO |
CVE-2004-0527MEDIUM KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, comb | Aug 6, 2004 | 5.0 | 24 | NO | YES |
CVE-2008-5712MEDIUM The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via (1) a long COLOR attribute in an HR element; or a long (a) BGCOL | Dec 24, 2008 | 5.0 | 23 | NO | YES |
CVE-2007-6000MEDIUM KDE Konqueror 3.5.6 and earlier allows remote attackers to cause a denial of service (crash) via large HTTP cookie parameters. | Nov 15, 2007 | 5.0 | 23 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (34 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
10 CVEs
29.4% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (34 CVEs).
Media Mentions
Signals from CVEs in this product scope (34 CVEs).
Top CNAs Publishing CVEs For Konqueror
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.95.00 | 1 | 4.3 | 0.8% | 0 | 0 |
| 3.5.9 | 2 | 5.0 | 2.5% | 0 | 1 |
| 3.5.7 | 3 | 4.6 | 2.1% | 0 | 0 |
| 3.5.5 | 7 | 5.3 | 2.8% | 0 | 2 |
| 3.3.2 | 3 | 5.5 | 3.6% | 0 | 1 |
| 3.3.1 | 4 | 6.0 | 3.8% | 0 | 2 |
| 3.3 | 3 | 5.5 | 3.6% | 0 | 1 |
| 3.2.3 | 7 | 6.3 | 5.9% | 0 | 1 |
| 3.2.2.6 | 3 | 5.5 | 3.6% | 0 | 1 |
| 3.2.2 | 2 | 5.0 | 4.2% | 0 | 1 |
| 3.2.1 | 9 | 6.0 | 5.4% | 0 | 2 |
| 3.1.5 | 7 | 6.3 | 5.9% | 0 | 1 |
| 3.1.4 | 6 | 6.1 | 6.6% | 0 | 1 |
| 3.1.3 | 9 | 6.3 | 5.4% | 0 | 2 |
| 3.1.2 | 10 | 6.2 | 5.5% | 0 | 2 |
| 3.1.1 | 10 | 6.2 | 5.5% | 0 | 2 |
| 3.1 | 10 | 6.2 | 5.5% | 0 | 2 |
| 3.0.5b | 7 | 6.3 | 5.9% | 0 | 1 |
| 3.0.5 | 10 | 6.2 | 5.5% | 0 | 2 |
| 3.0.3 | 12 | 6.1 | 5.2% | 0 | 3 |