← Vulnerability feed

Vulnerability record · CVE-2009-2702 · published 8 September 2009

CVE-2009-2702: Kdelibs vulnerability

Kde · Kdelibs

KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

7.5 CVSS 2.0 High EPSS 1.3% · top 31.6% CWE-310 · CWE-310
7.5CVSS 2.0 base score
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-2702 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2017-8422Kde kauth authentication bypass by spoofing vulnerabilityKDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper …EPSS 1.8%7.5CVE-2004-1165Kdelibs vulnerabilityKonqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FT…EPSS 4.4%7.0CVE-2015-7543Artsproject arts race condition vulnerabilityaRts 1.5.10 and kdelibs3 3.5.10 and earlier do not properly create temporary directories, which allows local users to hijack the IPC by pre-creating …EPSS 0.25%6.9CVE-2014-5033Debian kde4libs race condition vulnerabilityKDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypas…EPSS 0.36%5.5CVE-2017-6410Kdelibs cleartext transmission vulnerabilitykpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including…EPSS 0.83%5.0CVE-2013-2074Kdelibs information exposure vulnerabilitykioslave/http/http.cpp in KIO in kdelibs 4.10.3 and earlier allows attackers to discover credentials via a crafted request that triggers an "internal…EPSS 2.0%4.3CVE-2014-3494Opensuse information exposure vulnerabilitykio/usernotificationhandler.cpp in the POP3 kioslave in kdelibs 4.10.95 before 4.13.3 does not properly generate warning notifications, which allows …EPSS 0.71%

Source: NIST National Vulnerability Database (record CVE-2009-2702), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.