Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows remote attackers to bypass sandbox restrictions and read or write arbitrary files.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
20 Nov 2024, 23:50
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=110356286722875&w=2 - | |
References | () http://secunia.com/advisories/13586 - Patch, Vendor Advisory | |
References | () http://www.gentoo.org/security/en/glsa/glsa-200501-16.xml - Patch, Vendor Advisory | |
References | () http://www.heise.de/security/dienste/browsercheck/tests/java.shtml - Vendor Advisory | |
References | () http://www.kb.cert.org/vuls/id/420222 - Patch, Third Party Advisory, US Government Resource | |
References | () http://www.kde.org/info/security/advisory-20041220-1.txt - Patch, Vendor Advisory | |
References | () http://www.mandriva.com/security/advisories?name=MDKSA-2004:154 - | |
References | () http://www.redhat.com/support/errata/RHSA-2005-065.html - Patch, Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/18596 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10173 - |
Information
Published : 2004-12-15 05:00
Updated : 2024-11-20 23:50
NVD link : CVE-2004-1145
Mitre link : CVE-2004-1145
CVE.ORG link : CVE-2004-1145
JSON object : View
Products Affected
sgi
- propack
redhat
- enterprise_linux
- enterprise_linux_desktop
- linux_advanced_workstation
conectiva
- linux
ethereal_group
- ethereal
debian
- debian_linux
suse
- suse_linux
altlinux
- alt_linux
CWE