← Vulnerability feed

Vulnerability record · CVE-2004-1165 · published 10 January 2005

CVE-2004-1165: Kdelibs vulnerability

Kde · Kdelibs

Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.

7.5 CVSS 2.0 High EPSS 4.4% · top 9.0%
7.5CVSS 2.0 base score
4.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-1165 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2017-8422Kde kauth authentication bypass by spoofing vulnerabilityKDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper …EPSS 1.8%7.8CVE-2007-1565Kde konqueror vulnerabilityKonqueror 3.5.5 allows remote attackers to cause a denial of service (crash) by using JavaScript to read a child iframe having an ftp:// URI.EPSS 1.3%7.5CVE-2009-2702Kdelibs vulnerabilityKDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.50…EPSS 1.3%7.5CVE-2004-1158Kde konqueror vulnerabilityKonqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window i…EPSS 2.7%7.5CVE-2004-0867Kde konqueror permissions and access controls vulnerabilityMozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allo…EPSS 17%7.5CVE-2004-0746Kde konqueror vulnerabilityKonqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, whi…EPSS 1.9%7.5CVE-2004-0866Kde konqueror vulnerabilityInternet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allo…EPSS 10%7.5CVE-2004-0721Kde konqueror vulnerabilityKonqueror 3.1.3, 3.2.2, and possibly other versions does not properly prevent a frame in one domain from injecting content into a frame that belongs …EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2004-1165), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.