← Back

Kde

kde

191 CVEs • 56 products

Products (56)

Click to collapse
Toggle
Kde
kde
Konqueror
konqueror
Kde Sc
kde_sc
Kmail
kmail
Koffice
koffice
Kdelibs
kdelibs
Kpdf
kpdf
Kdegraphics
kdegraphics
K Mail
k-mail
Kde Workspace
kde-workspace
Ark
ark
Kword
kword
Kauth
kauth
Kvt
kvt
Kmplayer
kmplayer
Kio Extras
kio-extras
Messagelib
messagelib
Ktexteditor
ktexteditor
Trojita
trojita
Okular
okular
Paste Applet
paste_applet
Ktv
ktv
Kdeutils
kdeutils
Klisa
klisa
Kopete
kopete
Quanta
quanta
Dcopserver
dcopserver
Arts
arts
Kdebase
kdebase
Libkhtml
libkhtml
Ksirc
ksirc
Kget
kget
Kcheckpass
kcheckpass
Kde Pim
kde_pim
Plasma Desktop
plasma-desktop
Kde Runtime
kde-runtime
Kde Frameworks
kde_frameworks
Karchives
karchives
Kscreenlocker
kscreenlocker
Kde Cli Tools
kde-cli-tools
Kio
kio
Plasma
plasma
Kconfig
kconfig
Amarok
amarok
Kdeconnect
kdeconnect
Discover
discover
Kimageformats
kimageformats
Kate
kate
Kcron
kcron
Kde Beta 3
kde_beta_3
Kcoreaddons
kcoreaddons

CVEs (191)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Kde
1Paste Applet
Nov 21, 2024
Feb 11, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addons uses the GNU C Library rand function's linear congruential generator, which makes it easier for context-dependent attackers to defeat cryp...Show more
The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addons uses the GNU C Library rand function's linear congruential generator, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the generator output.Show less
1Kde
1Paste Applet
Nov 21, 2024
Feb 11, 2020
N/A· v4
8.4 HIGH· v3
2.1 LOW· v2
The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a...Show more
The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a brute-force attack.Show less
2Kde
Redhat
5Enterprise Linux
Enterprise Linux DesktopEnterprise Linux Server Eus+2 more
Nov 21, 2024
Feb 8, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."
2Debian
Kde
2Debian Linux
Kde Workspace
Nov 21, 2024
Dec 10, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
kde-workspace before 4.10.5 has a memory leak in plasma desktop
6Canonical
DebianFedoraproject+3 more
8Backports Sle
Debian LinuxEnterprise Linux Desktop+5 more
Nov 21, 2024
Aug 7, 2019
N/A· v4
7.8 HIGH· v3
5.1 MEDIUM· v2
In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .dir...Show more
In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.Show less
3Fedoraproject
KdeOpensuse
4Backports
FedoraKauth+1 more
Nov 21, 2024
May 7, 2019
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with...Show more
KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with dynamically loaded plugins. In other words, KAuth unintentionally causes this plugin code to run as root, which increases the severity of any possible exploitation of a plugin vulnerability.Show less
2Debian
Kde
2Debian Linux
Kmail
Nov 21, 2024
Apr 7, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline cha...Show more
In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this (benign looking) email, they unknowingly leak the plaintext of the encrypted message part(s) back to the attacker.Show less
1Kde
1Kde Applications
Nov 21, 2024
Nov 29, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leading to disclosure of the source IP address.
2Debian
Kde
2Debian Linux
Okular
Nov 21, 2024
Sep 6, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
okular version 18.08 and earlier contains a Directory Traversal vulnerability in function "unpackDocumentArchive(...)" in "core/document.cpp" that can result in Arbitrary file creation on the user workstation. This attac...Show more
okular version 18.08 and earlier contains a Directory Traversal vulnerability in function "unpackDocumentArchive(...)" in "core/document.cpp" that can result in Arbitrary file creation on the user workstation. This attack appear to be exploitable via he victim must open a specially crafted Okular archive. This issue appears to have been corrected in version 18.08.1Show less
169folders
AppleBloop+13 more
17Airmail
EmclientEvolution+14 more
Nov 21, 2024
May 16, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
3Debian
KdeOpensuse
3Debian Linux
LeapPlasma
Nov 21, 2024
May 8, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack.
1Kde
1Ktexteditor
Nov 21, 2024
Apr 25, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An issue was discovered in KTextEditor 5.34.0 through 5.45.0. Insecure handling of temporary files in the KTextEditor's kauth_ktexteditor_helper service (as utilized in the Kate text editor) can allow other unprivileged...Show more
An issue was discovered in KTextEditor 5.34.0 through 5.45.0. Insecure handling of temporary files in the KTextEditor's kauth_ktexteditor_helper service (as utilized in the Kate text editor) can allow other unprivileged users on the local system to gain root privileges. The attack occurs when one user (who has an unprivileged account but is also able to authenticate as root) writes a text file using Kate into a directory owned by a another unprivileged user. The latter unprivileged user conducts a symlink attack to achieve privilege escalation.Show less
2Debian
Kde
2Debian Linux
Plasma Workspace
Nov 21, 2024
Feb 7, 2018
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its volume label is plugged in and mounted through the device noti...Show more
An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its volume label is plugged in and mounted through the device notifier, it's interpreted as a shell command, leading to a possibility of arbitrary command execution. An example of an offending volume label is "$(touch b)" -- this will create a file called b in the home folder.Show less
1Kde
1Plasma Workspace
Nov 21, 2024
Feb 7, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the...Show more
An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the src attribute of an IMG element.Show less
1Kde
1Kmail
May 13, 2026
Sep 28, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
KDE KMail does not encrypt attachments in emails when "automatic encryption" is enabled, which allows remote attackers to obtain sensitive information by sniffing the network.
2Artsproject
Kde
2Arts
Kdelibs
May 13, 2026
Jul 25, 2017
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
aRts 1.5.10 and kdelibs3 3.5.10 and earlier do not properly create temporary directories, which allows local users to hijack the IPC by pre-creating the temporary directory.
1Kde
2Kmail
Messagelib
May 13, 2026
Jun 13, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote at...Show more
KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the network.Show less
1Kde
2Kauth
Kdelibs
May 13, 2026
May 17, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.
2Fedoraproject
Kde
2Ark
Fedora
May 13, 2026
Mar 27, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
ark before 16.12.1 might allow remote attackers to execute arbitrary code via an executable in an archive, related to associated applications.
1Kde
2Kdelibs
Kio
May 13, 2026
Mar 2, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which...Show more
kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.Show less