← Vulnerability feed

Vulnerability record · CVE-2006-0019 · published 20 January 2006

CVE-2006-0019: Kde vulnerability

Kde · Kde

Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI.

7.5 CVSS 2.0 High EPSS 6.1% · top 6.8%
7.5CVSS 2.0 base score
6.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
52References
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.3-kdelibs-kjs.diff Patch
http://secunia.com/advisories/18500 PatchVendor Advisory
http://secunia.com/advisories/18540 Vendor Advisory
http://secunia.com/advisories/18552
http://secunia.com/advisories/18559
http://secunia.com/advisories/18561 Vendor Advisory
http://secunia.com/advisories/18570
http://secunia.com/advisories/18583
http://secunia.com/advisories/18899
http://securityreason.com/securityalert/364
http://securitytracker.com/id?1015512
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.361107
http://www.debian.org/security/2006/dsa-948 Vendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200601-11.xml
http://www.kde.org/info/security/advisory-20060119-1.txt PatchVendor Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2006:019
http://www.osvdb.org/22659
http://www.redhat.com/support/errata/RHSA-2006-0184.html Vendor Advisory
http://www.securityfocus.com/archive/1/422464/100/0/threaded
http://www.securityfocus.com/archive/1/422489/100/0/threaded
http://www.securityfocus.com/archive/1/427976/100/0/threaded
http://www.securityfocus.com/bid/16325
http://www.ubuntu.com/usn/usn-245-1
http://www.vupen.com/english/advisories/2006/0265
https://exchange.xforce.ibmcloud.com/vulnerabilities/24242
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11858
ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.3-kdelibs-kjs.diff Patch
http://secunia.com/advisories/18500 PatchVendor Advisory
http://secunia.com/advisories/18540 Vendor Advisory
http://secunia.com/advisories/18552
http://secunia.com/advisories/18559
http://secunia.com/advisories/18561 Vendor Advisory
http://secunia.com/advisories/18570
http://secunia.com/advisories/18583
http://secunia.com/advisories/18899
http://securityreason.com/securityalert/364
http://securitytracker.com/id?1015512
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.361107
http://www.debian.org/security/2006/dsa-948 Vendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200601-11.xml

Track CVE-2006-0019 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-0011Kde vulnerabilityMultiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Interface (IND…EPSS 4.9%10.0CVE-2004-0888Easy software products cups vulnerabilityMultiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to …EPSS 9.5%10.0CVE-2004-0889Easy software products cups vulnerabilityMultiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (cras…EPSS 6.2%10.0CVE-2003-0690Kde vulnerabilityKDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by tri…EPSS 3.1%9.3CVE-2008-1670Kde memory buffer overflow vulnerabilityHeap-based buffer overflow in the progressive PNG Image loader (decoders/pngloader.cpp) in KHTML in KDE 4.0.x up to 4.0.3 allows remote attackers to …EPSS 4.8%9.3CVE-2004-1125Easy software products cups improper input validation vulnerabilityBuffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3…EPSS 6.6%8.8CVE-2012-4512Kde type confusion vulnerabilityThe CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read mem…EPSS 12%7.5CVE-2005-1852Ekg vulnerabilityMultiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, GNU Gadu, CenterICQ, Kadu, and other packages, all…EPSS 4.7%

Source: NIST National Vulnerability Database (record CVE-2006-0019), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.