SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-6660

The nodeType function in KDE libkhtml 4.2.0 and earlier, as used by Konquerer, KMail, and other programs, allows remote attackers to cause a denial of service (crash) via malformed HTML tags, possibly involving a COL SPAN tag embedded in a RANGE tag.

MEDIUM 4.3EPSS 2.48%

Does this matter?

Lower severity and a low EPSS score (2.48%). Track it; it rarely justifies an emergency change on its own.

Description

The nodeType function in KDE libkhtml 4.2.0 and earlier, as used by Konquerer, KMail, and other programs, allows remote attackers to cause a denial of service (crash) via malformed HTML tags, possibly involving a COL SPAN tag embedded in a RANGE tag.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
EPSS
2.48% probability · 84th percentile
CISA KEV
Not listed
Affected
kde/libkhtml
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.