[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2012-4512Date: (C)2020-02-10   (M)2023-12-22


The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 8.8CVSS Score : 6.8
Exploit Score: 2.8Exploit Score: 8.6
Impact Score: 5.9Impact Score: 6.4
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: MEDIUM
Privileges Required: NONEAuthentication: NONE
User Interaction: REQUIREDConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: HIGHAvailability: PARTIAL
Integrity: HIGH 
Availability: HIGH 
  
Reference:
http://archives.neohapsis.com/archives/bugtraq/2012-11/0005.html
http://em386.blogspot.com/2010/12/webkit-css-type-confusion.html
http://quickgit.kde.org/index.php?p=kdelibs.git&a=commitdiff&h=a872c8a969a8bd3706253d6ba24088e4f07f3352
http://rhn.redhat.com/errata/RHSA-2012-1416.html
http://rhn.redhat.com/errata/RHSA-2012-1418.html
http://secunia.com/advisories/51097
http://secunia.com/advisories/51145
http://www.nth-dimension.org.uk/pub/NDSA20121010.txt.asc
http://www.openwall.com/lists/oss-security/2012/10/11/11
http://www.openwall.com/lists/oss-security/2012/10/30/6
http://www.securitytracker.com/id?1027709

CWE    1
CWE-843
OVAL    6
oval:org.secpod.oval:def:1500011
oval:org.secpod.oval:def:500918
oval:org.secpod.oval:def:202485
oval:org.secpod.oval:def:202484
...

© SecPod Technologies