Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-19120

EPSS 0.27% · P50
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2018-19120

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leading to disclosure of the source IP address.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
KDE kio-extras HTML Thumbnailer插件信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
KDE是Linux和Unix工作站的一款免费开放源代码X桌面管理程序,KDE提供通过KIO子系统支持各种网络协议。kio-extras是其中的一个用于增加KIO功能的组件。HTML Thumbnailer plug-in是其中的一个缩略图插件。 KDE 18.12.0之前版本中的kio-extras的HTML Thumbnailer插件存在输入验证漏洞,该漏洞源于程序允许用户访问HTML文件中的远程URLs信息。远程攻击者可利用该漏洞访问敏感信息,例如:IP地址。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2018-19120

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2018-19120

Please Login to view more intelligence information

Same Patch Batch · n/a · 2018-11-29 · 28 CVEs total

CVE-2018-18649GitLab 输入验证错误漏洞
CVE-2018-19527i4 assistant 跨站脚本漏洞
CVE-2018-19497The Sleuth Kit 安全漏洞
CVE-2018-19752DomainMod 跨站脚本漏洞
CVE-2018-19751DomainMod 跨站脚本漏洞
CVE-2018-19750DomainMod 跨站脚本漏洞
CVE-2018-19749DomainMod 跨站脚本漏洞
CVE-2018-18619Advanced Comment SQL注入漏洞
CVE-2018-19748SDCMS 路径遍历漏洞
CVE-2018-15537OCS Inventory NG ocsreports 安全漏洞
CVE-2018-15978Adobe Flash Player 缓冲区错误漏洞
CVE-2018-19693tp5cms 跨站脚本漏洞
CVE-2018-19692tp5cms 安全漏洞
CVE-2018-11002Pulse Secure Desktop Client for Windows 安全漏洞
CVE-2018-19622Wireshark MMSE解析器安全漏洞
CVE-2018-19666OSSEC 路径遍历漏洞
CVE-2018-19664libjpeg-turbo 缓冲区错误漏洞
CVE-2018-19662libsndfile 缓冲区错误漏洞
CVE-2018-19661libsndfile 缓冲区错误漏洞
CVE-2018-19655dcraw 缓冲区错误漏洞

Showing top 20 of 28 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2018-19120

No comments yet


Leave a comment