CVE-2003-0370 PUBLISHED CVSS 7.5 HIGH

Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.

EPSS 0.94% · 76.1th percentile

Risk Scores

CVSS v2.0
7.5
EPSS Score
0.94%
76.1th percentile

Affected Products

VendorProductVersions
kdekonqueror_embedded0.1
applesafari1.0, 1.0
n/an/an/a
turbolinuxturbolinux_workstation8.0, 7.0
kdekde0
redhatlinux7.2, 7.1
turbolinuxturbolinux_server7.0, 8.0

Timeline

References

Open in Interactive Console →