← Vulnerability feed

Vulnerability record · CVE-2004-0411 · published 7 July 2004

CVE-2004-0411: Kde konqueror argument injection vulnerability

Kde · Konqueror

The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attackers to manipulate the options that are passed to the associated programs, possibly to read arbitrary files or execute arbitrary code.

7.5 CVSS 2.0 High EPSS 7.8% · top 5.6% CWE-88 · Argument injection
7.5CVSS 2.0 base score
7.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
34References
16 Jun 2026Last modified by NVD

Description

The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attackers to manipulate the options that are passed to the associated programs, possibly to read arbitrary files or execute arbitrary code.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000843 Broken Link
http://marc.info/?l=bugtraq&m=108481412427344&w=2 Mailing ListThird Party Advisory
http://secunia.com/advisories/11602 Broken Link
http://security.gentoo.org/glsa/glsa-200405-11.xml Third Party Advisory
http://www.ciac.org/ciac/bulletins/o-146.shtml Broken Link
http://www.debian.org/security/2004/dsa-518 Third Party Advisory
http://www.kde.org/info/security/advisory-20040517-1.txt PatchVendor Advisory
http://www.novell.com/linux/security/advisories/2004_14_kdelibs.html Broken Link
http://www.osvdb.org/6107 Broken Link
http://www.redhat.com/support/errata/RHSA-2004-222.html Broken Link
http://www.securityfocus.com/advisories/6717 Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/advisories/6743 Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/363225 Broken LinkThird Party AdvisoryVDB EntryVendor Advisory
http://www.securityfocus.com/bid/10358 Broken LinkThird Party AdvisoryVDB Entry
http://www.slackware.org/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.362635 Broken Link
https://exchange.xforce.ibmcloud.com/vulnerabilities/16163 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A954 Broken LinkTool Signature
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000843 Broken Link
http://marc.info/?l=bugtraq&m=108481412427344&w=2 Mailing ListThird Party Advisory
http://secunia.com/advisories/11602 Broken Link
http://security.gentoo.org/glsa/glsa-200405-11.xml Third Party Advisory
http://www.ciac.org/ciac/bulletins/o-146.shtml Broken Link
http://www.debian.org/security/2004/dsa-518 Third Party Advisory
http://www.kde.org/info/security/advisory-20040517-1.txt PatchVendor Advisory
http://www.novell.com/linux/security/advisories/2004_14_kdelibs.html Broken Link
http://www.osvdb.org/6107 Broken Link
http://www.redhat.com/support/errata/RHSA-2004-222.html Broken Link
http://www.securityfocus.com/advisories/6717 Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/advisories/6743 Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/363225 Broken LinkThird Party AdvisoryVDB EntryVendor Advisory
http://www.securityfocus.com/bid/10358 Broken LinkThird Party AdvisoryVDB Entry
http://www.slackware.org/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.362635 Broken Link
https://exchange.xforce.ibmcloud.com/vulnerabilities/16163 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A954 Broken LinkTool Signature

Track CVE-2004-0411 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2007-1565Kde konqueror vulnerabilityKonqueror 3.5.5 allows remote attackers to cause a denial of service (crash) by using JavaScript to read a child iframe having an ftp:// URI.EPSS 1.3%7.5CVE-2004-1158Kde konqueror vulnerabilityKonqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window i…EPSS 2.7%7.5CVE-2004-1165Kdelibs vulnerabilityKonqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FT…EPSS 4.4%7.5CVE-2004-0867Kde konqueror permissions and access controls vulnerabilityMozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allo…EPSS 17%7.5CVE-2004-0746Kde konqueror vulnerabilityKonqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, whi…EPSS 1.9%7.5CVE-2004-0866Kde konqueror vulnerabilityInternet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allo…EPSS 10%7.5CVE-2004-0721Kde konqueror vulnerabilityKonqueror 3.1.3, 3.2.2, and possibly other versions does not properly prevent a frame in one domain from injecting content into a frame that belongs …EPSS 1.6%7.5CVE-2003-0592Kde konqueror vulnerabilityKonqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" …EPSS 4.4%

Source: NIST National Vulnerability Database (record CVE-2004-0411), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.