security flaw
Published Jan 20, 2006
7.5
HIGHCVSS 2.0
EPSS 6.14%
Description
Heap-based buffer overflow in the encodeURI and decodeURI functions in the kjs JavaScript interpreter engine in KDE 3.2.0 through 3.5.0 allows remote attackers to execute arbitrary code via a crafted, UTF-8 encoded URI.
Affected products
No data.
- 3.2
- 3.2.0
- 3.2.0_beta1
- 3.2.1
- 3.2.2
- 3.2.3
- 3.2.x
- 3.3
- 3.3.0
- 3.3.1
- 3.3.2
- 3.3.x
- 3.4
- 3.4.0
- 3.4.1
- 3.4.2
- 3.5.0
No data.
Red Hat Enterprise Linux 4
kdelibs-6:3.3.1-3.14
Fixed · RHSA-2006:0184
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | kdelibs-6:3.3.1-3.14 | Fixed | RHSA-2006:0184 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 6.14% (0.06140) | 93.24th | v5 (v2026.06.15) |
| Jun 15, 2026 | 6.00% (0.05999) | 92.37th | v5 (v2026.06.15) |
| Jun 25, 2025 | 6.39% (0.06387) | 90.54th | v4 (v2025.03.14) |
| Mar 30, 2025 | 5.32% (0.05323) | 89.08th | v4 (v2025.03.14) |
| Mar 29, 2025 | 7.83% (0.07825) | 86.37th | v4 (v2025.03.14) |
| Mar 17, 2025 | 5.32% (0.05323) | 89.34th | v4 (v2025.03.14) |
| Dec 27, 2024 | 14.81% (0.14810) | 95.77th | v3 (v2023.03.01) |
| Dec 17, 2024 | 25.17% (0.25168) | 96.68th | v3 (v2023.03.01) |
| Mar 7, 2023 | 17.27% (0.17265) | 95.20th | v3 (v2023.03.01) |
| Mar 6, 2023 | 12.25% (0.12248) | 95.30th | v2 (v2022.01.01) |
| Apr 1, 2022 | 12.25% (0.12248) | 94.93th | v2 (v2022.01.01) |
| Feb 4, 2022 | 12.25% (0.12248) | 89.34th | v2 (v2022.01.01) |
No CWE recorded.
References (30)
- ftp://ftp.kde.org/pub/kde/security_patches/post-3.4.3-kdelibs-kjs.diff x_refsource_CONFIRMPatch
- http://secunia.com/advisories/18500 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/18540 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18552 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18559 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18561 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18570 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18583 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/18899 third-party-advisoryx_refsource_SECUNIA
- http://securityreason.com/securityalert/364 third-party-advisoryx_refsource_SREASON
- http://securitytracker.com/id?1015512 vdb-entryx_refsource_SECTRACK
- http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.361107 vendor-advisoryx_refsource_SLACKWARE
- http://www.debian.org/security/2006/dsa-948 vendor-advisoryx_refsource_DEBIANVendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200601-11.xml vendor-advisoryx_refsource_GENTOO
- http://www.kde.org/info/security/advisory-20060119-1.txt x_refsource_CONFIRMPatchVendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:019 vendor-advisoryx_refsource_MANDRIVA
- http://www.osvdb.org/22659 vdb-entryx_refsource_OSVDB
- http://www.redhat.com/support/errata/RHSA-2006-0184.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://www.securityfocus.com/archive/1/422464/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/422489/100/0/threaded vendor-advisoryx_refsource_SUSE
- http://www.securityfocus.com/archive/1/427976/100/0/threaded vendor-advisoryx_refsource_FEDORA
- http://www.securityfocus.com/bid/16325 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/usn-245-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2006/0265 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2006-0019 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1617866 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24242 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2006-0019
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11858 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2006-0019
Change history (0)
No recorded changes yet.