CVE-2004-1145
Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows remote attackers to bypass…
Does this matter?
Lower severity and a low EPSS score (4.13%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows remote attackers to bypass sandbox restrictions and read or write arbitrary files.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 4.13% probability · 90th percentile
- CISA KEV
- Not listed
- Affected
- ethereal group/ethereal · sgi/propack · conectiva/linux · altlinux/alt linux · debian/debian linux · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/linux advanced workstation · suse/suse linux
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=110356286722875&w=2
- http://secunia.com/advisories/13586Patch, Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200501-16.xmlPatch, Vendor Advisory
- http://www.heise.de/security/dienste/browsercheck/tests/java.shtmlVendor Advisory
- http://www.kb.cert.org/vuls/id/420222Patch, Third Party Advisory, US Government Resource
- http://www.kde.org/info/security/advisory-20041220-1.txtPatch, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:154
- http://www.redhat.com/support/errata/RHSA-2005-065.htmlPatch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18596
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10173
- http://marc.info/?l=bugtraq&m=110356286722875&w=2
- http://secunia.com/advisories/13586Patch, Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200501-16.xmlPatch, Vendor Advisory
- http://www.heise.de/security/dienste/browsercheck/tests/java.shtmlVendor Advisory
- http://www.kb.cert.org/vuls/id/420222Patch, Third Party Advisory, US Government Resource
- http://www.kde.org/info/security/advisory-20041220-1.txtPatch, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:154
- http://www.redhat.com/support/errata/RHSA-2005-065.htmlPatch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18596
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10173
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.