VDB
CVE-2012-4513
CVE-2012-4513
PUBLISHED
CVSS 6.400000095367432 MEDIUM
khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via large canvas dimensions, which leads to an unexpected sign extension and a heap-based buffer over-read.
EPSS 15.12% · 94.7th percentile
Risk Scores
CVSS 2.0
6.400000095367432
EPSS Score
15.12%
94.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| kde | kde | 4.7.3 |
Timeline
- Oct 31, 2012 PoC Published
- Nov 11, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 3, 2023 EPSS Score
- Feb 9, 2023 EPSS Score
- Feb 13, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- http://quickgit.kde.org/index.php?p=kdelibs.git&a=commitdiff&h=1f8b1b034ccf1713a5d123a4c327290f86d17d53 url
- 51145 third-party-advisory
- RHSA-2012:1418 vendor-advisory
- RHSA-2012:1416 vendor-advisory
- 1027709 vdb
- http://www.nth-dimension.org.uk/pub/NDSA20121010.txt.asc url
- [oss-security] 20121011 Re: Pre-advisory for Konqueror 4.7.3 (other versions may be affected) mailing-list
- 20121030 Medium risk security flaws in Konqueror mailing-list
- [oss-security] 20121030 Medium risk security flaws in Konqueror mailing-list
- 51097 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2012-4513 advisory