The latest CVE Vulnerability List for redhat/analog_real-time_synthesizer

 

Page content

redhat/analog_real-time_synthesizer Vulnerability Summary

  • Vendor name: redhat
  • Product name: analog_real-time_synthesizer
  • Total vulnerabilities: 1 (as 2023-04-30)

redhat/analog_real-time_synthesizer Vulnerability List

CVE-2003-0459: KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of…

Published: 2003-08-27T04:00:00 Last Modified: 2017-10-11T01:29:00

Summary

KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the “user:password@host” form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.

Common Weakness Enumeration (CWE): NVD-CWE-Other

Scores

  • Impact Score: 2.9
  • Exploitability Score: 10.0
  • CVSS: 5.0
  • CVSS Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Impact

  • Availability: NONE
  • Confidentiality: PARTIAL
  • Integrity: NONE

References

See also: All popular products CVE Vulnerabilities of redhat