The KDE HTML library (kdelibs), as used by Konqueror 3.5.5, does not properly parse HTML comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within a comment in a title tag, a related issue to CVE-2007-0478.
CVSS Details
- CVSS 3.1 Base Score: 3.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade kde-base/kdelibs. | Oct 30, 2017 | Jan 29, 2007 |
| Oracle_linux | — | Upgrade kdelibs-apidocsUpgrade kdelibsUpgrade kdelibs-devel | Oct 16, 2024 | Jan 29, 2007 |
| Suse | — | Upgrade kdelibs3-x86Upgrade kdelibs3-32bitUpgrade suse-releaseUpgrade kdelibs3-develUpgrade kdelibs3Upgrade kdelibs3-64bit | Feb 17, 2015 | Jan 29, 2007 |
| Ubuntu | — | Upgrade kdelibs4c2aUpgrade kdelibs4c2 | Nov 8, 2024 | Jan 29, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub