SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2004-1145

Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows remote attackers to bypass…

MEDIUM 5.0EPSS 4.13%

Does this matter?

Lower severity and a low EPSS score (4.13%). Track it; it rarely justifies an emergency change on its own.

Description

Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows remote attackers to bypass sandbox restrictions and read or write arbitrary files.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
4.13% probability · 90th percentile
CISA KEV
Not listed
Affected
ethereal group/ethereal · sgi/propack · conectiva/linux · altlinux/alt linux · debian/debian linux · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/linux advanced workstation · suse/suse linux
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.