VDB
CVE-2007-0537
CVE-2007-0537
PUBLISHED
Reported by mitre · Published January 29, 2007
The KDE HTML library (kdelibs), as used by Konqueror 3.5.5, does not properly parse HTML comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within a comment in a title tag, a related issue to CVE-2007-0478.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | n/a, n/a, n/a |
Timeline
- Jun 1, 2006 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
- Dec 3, 2023 EPSS Score
References
- RHSA-2007:0909 vendor-advisoryx_refsource_REDHAT
- MDKSA-2007:157 vendor-advisoryx_refsource_MANDRIVA
- 24889 third-party-advisoryx_refsource_SECUNIA
- 23932 third-party-advisoryx_refsource_SECUNIA
- SUSE-SR:2007:006 vendor-advisoryx_refsource_SUSE
- x_refsource_CONFIRM
- 32975 vdb-entryx_refsource_OSVDB
- GLSA-200703-10 vendor-advisoryx_refsource_GENTOO
- 20070124 Re: Safari Improperly Parses HTML Documents & BlogSpot XSS vulnerability mailing-listx_refsource_BUGTRAQ
- USN-420-1 vendor-advisoryx_refsource_UBUNTU
- 27108 third-party-advisoryx_refsource_SECUNIA
- x_refsource_CONFIRM
- 24463 third-party-advisoryx_refsource_SECUNIA
- 1017591 vdb-entryx_refsource_SECTRACK
- 24065 third-party-advisoryx_refsource_SECUNIA
- 24013 third-party-advisoryx_refsource_SECUNIA
- oval:org.mitre.oval:def:10244 vdb-entrysignaturex_refsource_OVAL
- MDKSA-2007:031 vendor-advisoryx_refsource_MANDRIVA
- ADV-2007-0505 vdb-entryx_refsource_VUPEN
- 22428 vdb-entryx_refsource_BID
…and 1 more