CVE-2014-8600

KDE-Runtime < 4.14.2, kwebkitpart < 1.3.3, kio-extras < 5.1.1 - Cross-Site Scripting via Crafted URI Schemes

Title source: llm
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in KDE-Runtime 4.14.3 and earlier, kwebkitpart 1.3.4 and earlier, and kio-extras 5.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via a crafted URI using the (1) zip, (2) trash, (3) tar, (4) thumbnail, (5) smtps, (6) smtp, (7) smb, (8) remote, (9) recentdocuments, (10) nntps, (11) nntp, (12) network, (13) mbox, (14) ldaps, (15) ldap, (16) fonts, (17) file, (18) desktop, (19) cgi, (20) bookmarks, or (21) ar scheme, which is not properly handled in an error message.

References (5)

Core 5
Core References
Patch, Vendor Advisory vendor-advisory x_refsource_ubuntu
http://ubuntu.com/usn/usn-2414-1
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2015-03/msg00068.html
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Nov/54
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/71190

Scores

EPSS 0.0028
EPSS Percentile 51.7%

Details

CWE
CWE-79
Status published
Products (4)
kde/kde-runtime < 4.14.2
kde/kio-extras < 5.1.1
opensuse/opensuse 13.1
urs_wolfer/kwebkitpart < 1.3.3
Published Dec 08, 2014
Tracked Since Feb 18, 2026