HIGH · 7.5

CVE-2005-0754

Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code.

Vulnerability Description

Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
KdeQuanta3.1
ConectivaLinux9.0
GentooLinuxAll versions
KdeKde3.2
RedhatFedora Corecore_3.0
UbuntuUbuntu Linux4.1

References

FAQ

What is CVE-2005-0754?

CVE-2005-0754 is a vulnerability with a CVSS score of 7.5 (HIGH). Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code.

How severe is CVE-2005-0754?

CVE-2005-0754 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-0754?

Check the references section above for vendor advisories and patch information. Affected products include: Kde Quanta, Conectiva Linux, Gentoo Linux, Kde Kde, Redhat Fedora Core.