Back to Database
Status published
Medium
CVE-2007-4225
Visual truncation vulnerability in KDE Konqueror 3.5.7 allows remote attackers...
Vulnerability Description
Visual truncation vulnerability in KDE Konqueror 3.5.7 allows remote attackers to spoof the URL address bar via an http URI with a large amount of whitespace in the user/password portion.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-4225
Credits & Attribution
No credits recorded in the NVD database.
References
- http://securityreason.com/securityalert/2982
- https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00022.html
- https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00084.html
- http://www.ubuntu.com/usn/usn-502-1
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35829
- http://www.vupen.com/english/advisories/2007/2807
- http://secunia.com/advisories/26351
- http://secunia.com/advisories/26690
- http://securitytracker.com/id?1018579
- http://secunia.com/advisories/27089
- http://secunia.com/advisories/26612
- http://secunia.com/advisories/27096
- http://secunia.com/advisories/26720
- https://issues.rpath.com/browse/RPL-1615
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:176
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-August/065101.html
- http://www.kde.org/info/security/advisory-20070816-1.txt
More from kde
View All →CVE-2022-24986
KDE KCron through 21.12.2 uses a temporary file in /tmp...
High
7.8
CVE-2022-23853
The LSP (Language Server Protocol) plugin in KDE Kate before...
High
7.8
CVE-2021-38373
In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option...
Medium
5.3
CVE-2021-38372
In KDE Trojita 0.7, man-in-the-middle attackers can create new folders...
Low
3.7
CVE-2021-36083
KDE KImageFormats 5.70.0 through 5.81.0 has a stack-based buffer overflow...
Medium
5.5
Affected Vendor
Affected Software
konqueror
Vulnerable Versions:
3.5.7
Timeline
Official Publish:
August 8th, 2007
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.