CVE Vulnerabilities

CVE-2004-0746

Published: Oct 20, 2004 | Modified: Oct 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, which could allow remote attackers to perform a session fixation attack and hijack a users HTTP session.

Affected Software

Name Vendor Start Version End Version
Konqueror Kde 3.0 (including) 3.0 (including)
Konqueror Kde 3.0.1 (including) 3.0.1 (including)
Konqueror Kde 3.0.2 (including) 3.0.2 (including)
Konqueror Kde 3.0.3 (including) 3.0.3 (including)
Konqueror Kde 3.0.5 (including) 3.0.5 (including)
Konqueror Kde 3.0.5b (including) 3.0.5b (including)
Konqueror Kde 3.1 (including) 3.1 (including)
Konqueror Kde 3.1.1 (including) 3.1.1 (including)
Konqueror Kde 3.1.2 (including) 3.1.2 (including)
Konqueror Kde 3.1.3 (including) 3.1.3 (including)
Konqueror Kde 3.1.5 (including) 3.1.5 (including)
Konqueror Kde 3.2.1 (including) 3.2.1 (including)
Konqueror Kde 3.2.3 (including) 3.2.3 (including)
Red Hat Enterprise Linux 3 RedHat kdebase-6:3.1.3-5.4 *
Red Hat Enterprise Linux 3 RedHat kdelibs-6:3.1.3-6.6 *

References