FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2023-01-25 11:36:57 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
890b6b22-70fa-11e4-91ae-5453ed2e2b49kwebkitpart, kde-runtime -- insufficient input validation

Albert Aastals Cid reports:

kwebkitpart and the bookmarks:// io slave were not sanitizing input correctly allowing to some javascript being executed on the context of the referenced hostname.

Whilst in most cases, the JavaScript will be executed in an untrusted context, with the bookmarks IO slave, it will be executed in the context of the referenced hostname. It should however be noted that KDE mitigates this risk by attempting to ensure that such URLs cannot be embedded directly into Internet hosted content.


Discovery 2014-11-13
Entry 2014-11-20
kde-runtime
lt 4.14.2_2

kwebkitpart
lt 1.3.2_4

https://www.kde.org/info/security/advisory-20141113-1.txt
CVE-2014-8600