SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-0537

The KDE HTML library (kdelibs), as used by Konqueror 3.5.5, does not properly parse HTML comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within a…

LOW 2.6EPSS 1.85%

Does this matter?

Lower severity and a low EPSS score (1.85%). Track it; it rarely justifies an emergency change on its own.

Description

The KDE HTML library (kdelibs), as used by Konqueror 3.5.5, does not properly parse HTML comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within a comment in a title tag, a related issue to CVE-2007-0478.

CVSS 2.0
2.6 LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
EPSS
1.85% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
kde/konqueror
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.