CVE-2007-0537
The KDE HTML library (kdelibs), as used by Konqueror 3.5.5, does not properly parse HTML comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within a…
Does this matter?
Lower severity and a low EPSS score (1.85%). Track it; it rarely justifies an emergency change on its own.
Description
The KDE HTML library (kdelibs), as used by Konqueror 3.5.5, does not properly parse HTML comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within a comment in a title tag, a related issue to CVE-2007-0478.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
- EPSS
- 1.85% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- kde/konqueror
- Source
- cve@mitre.org
References
- http://osvdb.org/32975
- http://secunia.com/advisories/23932Vendor Advisory
- http://secunia.com/advisories/24013Vendor Advisory
- http://secunia.com/advisories/24065Vendor Advisory
- http://secunia.com/advisories/24442Vendor Advisory
- http://secunia.com/advisories/24463Vendor Advisory
- http://secunia.com/advisories/24889Vendor Advisory
- http://secunia.com/advisories/27108Vendor Advisory
- http://securitytracker.com/id?1017591
- http://www.gentoo.org/security/en/glsa/glsa-200703-10.xml
- http://www.kde.org/info/security/advisory-20070206-1.txt
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:031
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:157
- http://www.novell.com/linux/security/advisories/2007_6_sr.html
- http://www.redhat.com/support/errata/RHSA-2007-0909.html
- http://www.securityfocus.com/archive/1/457924/100/0/threaded
- http://www.securityfocus.com/bid/22428
- http://www.ubuntu.com/usn/usn-420-1
- http://www.vupen.com/english/advisories/2007/0505Vendor Advisory
- https://issues.rpath.com/browse/RPL-1117
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10244
- http://osvdb.org/32975
- http://secunia.com/advisories/23932Vendor Advisory
- http://secunia.com/advisories/24013Vendor Advisory
- http://secunia.com/advisories/24065Vendor Advisory
- http://secunia.com/advisories/24442Vendor Advisory
- http://secunia.com/advisories/24463Vendor Advisory
- http://secunia.com/advisories/24889Vendor Advisory
- http://secunia.com/advisories/27108Vendor Advisory
- http://securitytracker.com/id?1017591
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.