← Vulnerability feed

Vulnerability record · CVE-2017-6410 · published 2 March 2017

CVE-2017-6410: Kdelibs cleartext transmission vulnerability

Kde · Kdelibs

kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.

5.5 CVSS 3.0 Medium EPSS 0.83% · top 44.2% CWE-319 · Cleartext transmission
5.5CVSS 3.0 base score, v2 4.3
0.83%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-6410 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2017-8422Kde kauth authentication bypass by spoofing vulnerabilityKDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper …EPSS 1.8%7.5CVE-2009-2702Kdelibs vulnerabilityKDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.50…EPSS 1.3%7.5CVE-2004-1165Kdelibs vulnerabilityKonqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FT…EPSS 4.4%7.0CVE-2015-7543Artsproject arts race condition vulnerabilityaRts 1.5.10 and kdelibs3 3.5.10 and earlier do not properly create temporary directories, which allows local users to hijack the IPC by pre-creating …EPSS 0.25%6.9CVE-2014-5033Debian kde4libs race condition vulnerabilityKDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypas…EPSS 0.36%5.0CVE-2013-2074Kdelibs information exposure vulnerabilitykioslave/http/http.cpp in KIO in kdelibs 4.10.3 and earlier allows attackers to discover credentials via a crafted request that triggers an "internal…EPSS 2.0%4.3CVE-2014-3494Opensuse information exposure vulnerabilitykio/usernotificationhandler.cpp in the POP3 kioslave in kdelibs 4.10.95 before 4.13.3 does not properly generate warning notifications, which allows …EPSS 0.71%

Source: NIST National Vulnerability Database (record CVE-2017-6410), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.