← Vulnerability feed

Vulnerability record · CVE-2007-1308 · published 7 March 2007

CVE-2007-1308: Kde konqueror vulnerability

Kde · Konqueror

ecma/kjs_html.cpp in KDE JavaScript (KJS), as used in Konqueror in KDE 3.5.5, allows remote attackers to cause a denial of service (crash) by accessing the content of an iframe with an ftp:// URI in the src attribute, probably due to a NULL pointer dereference.

4.3 CVSS 2.0 Medium EPSS 8.2% · top 5.3% CWE-399 · CWE-399
4.3CVSS 2.0 base score
8.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
26References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

ecma/kjs_html.cpp in KDE JavaScript (KJS), as used in Konqueror in KDE 3.5.5, allows remote attackers to cause a denial of service (crash) by accessing the content of an iframe with an ftp:// URI in the src attribute, probably due to a NULL pointer dereference.

AV:N/AC:M/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://bindshell.net/advisories/konq355 ExploitPatchVendor Advisory
http://bindshell.net/advisories/konq355/konq355-patch.diff
http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/052793.html ExploitPatch
http://secunia.com/advisories/27108 Vendor Advisory
http://securityreason.com/securityalert/2345
http://www.mandriva.com/security/advisories?name=MDKSA-2007:054
http://www.redhat.com/support/errata/RHSA-2007-0909.html
http://www.securityfocus.com/archive/1/461897/100/0/threaded
http://www.securityfocus.com/bid/22814 Exploit
http://www.ubuntu.com/usn/usn-447-1
http://www.vupen.com/english/advisories/2007/0886
https://exchange.xforce.ibmcloud.com/vulnerabilities/32798
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10551
http://bindshell.net/advisories/konq355 ExploitPatchVendor Advisory
http://bindshell.net/advisories/konq355/konq355-patch.diff
http://lists.grok.org.uk/pipermail/full-disclosure/2007-March/052793.html ExploitPatch
http://secunia.com/advisories/27108 Vendor Advisory
http://securityreason.com/securityalert/2345
http://www.mandriva.com/security/advisories?name=MDKSA-2007:054
http://www.redhat.com/support/errata/RHSA-2007-0909.html
http://www.securityfocus.com/archive/1/461897/100/0/threaded
http://www.securityfocus.com/bid/22814 Exploit
http://www.ubuntu.com/usn/usn-447-1
http://www.vupen.com/english/advisories/2007/0886
https://exchange.xforce.ibmcloud.com/vulnerabilities/32798
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10551

Track CVE-2007-1308 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2007-1565Kde konqueror vulnerabilityKonqueror 3.5.5 allows remote attackers to cause a denial of service (crash) by using JavaScript to read a child iframe having an ftp:// URI.EPSS 1.3%7.5CVE-2004-1158Kde konqueror vulnerabilityKonqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window i…EPSS 2.7%7.5CVE-2004-1165Kdelibs vulnerabilityKonqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FT…EPSS 4.4%7.5CVE-2004-0867Kde konqueror permissions and access controls vulnerabilityMozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allo…EPSS 17%7.5CVE-2004-0746Kde konqueror vulnerabilityKonqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, whi…EPSS 1.9%7.5CVE-2004-0866Kde konqueror vulnerabilityInternet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allo…EPSS 10%7.5CVE-2004-0721Kde konqueror vulnerabilityKonqueror 3.1.3, 3.2.2, and possibly other versions does not properly prevent a frame in one domain from injecting content into a frame that belongs …EPSS 1.6%7.5CVE-2004-0411Kde konqueror argument injection vulnerabilityThe URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) …EPSS 7.8%

Source: NIST National Vulnerability Database (record CVE-2007-1308), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.