← Vulnerability feed

Vulnerability record · CVE-2004-0527 · published 6 August 2004

CVE-2004-0527: Kde konqueror vulnerability

Kde · Konqueror

KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.

5.0 CVSS 2.0 Medium EPSS 5.8% · top 7.2%
5.0CVSS 2.0 base score
5.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.

AV:N/AC:L/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-0527 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2007-1565Kde konqueror vulnerabilityKonqueror 3.5.5 allows remote attackers to cause a denial of service (crash) by using JavaScript to read a child iframe having an ftp:// URI.EPSS 1.3%7.5CVE-2004-1158Kde konqueror vulnerabilityKonqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window i…EPSS 2.7%7.5CVE-2004-1165Kdelibs vulnerabilityKonqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FT…EPSS 4.4%7.5CVE-2004-0867Kde konqueror permissions and access controls vulnerabilityMozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allo…EPSS 17%7.5CVE-2004-0746Kde konqueror vulnerabilityKonqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, whi…EPSS 1.9%7.5CVE-2004-0866Kde konqueror vulnerabilityInternet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allo…EPSS 10%7.5CVE-2004-0721Kde konqueror vulnerabilityKonqueror 3.1.3, 3.2.2, and possibly other versions does not properly prevent a frame in one domain from injecting content into a frame that belongs …EPSS 1.6%7.5CVE-2004-0411Kde konqueror argument injection vulnerabilityThe URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) …EPSS 7.8%

Source: NIST National Vulnerability Database (record CVE-2004-0527), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.