Vulnerability Name:

CVE-2007-0537 (CCN-31935)

Assigned:2007-01-24
Published:2007-01-24
Updated:2018-10-16
Summary:The KDE HTML library (kdelibs), as used by Konqueror 3.5.5, does not properly parse HTML comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within a comment in a title tag, a related issue to CVE-2007-0478.
CVSS v3 Severity:4.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N)
2.2 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N)
3.5 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-79
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: BugTraq Mailing List, Tue Jan 23 2007 - 01:44:13 CST
Safari Improperly Parses HTML Documents & BlogSpot XSS vulnerability

Source: CCN
Type: BugTraq Mailing List, Tue Jan 23 2007 - 23:06:34 CST
Re: Safari Improperly Parses HTML Documents & BlogSpot XSS vulnerability

Source: MITRE
Type: CNA
CVE-2007-0537

Source: OSVDB
Type: UNKNOWN
32975

Source: CCN
Type: RHSA-2007-0909
Moderate: kdelibs security update

Source: CCN
Type: SA23932
Konqueror HTML Parsing Weakness

Source: SECUNIA
Type: Vendor Advisory
23932

Source: SECUNIA
Type: Vendor Advisory
24013

Source: SECUNIA
Type: Vendor Advisory
24065

Source: SECUNIA
Type: Vendor Advisory
24442

Source: SECUNIA
Type: Vendor Advisory
24463

Source: SECUNIA
Type: Vendor Advisory
24889

Source: SECUNIA
Type: Vendor Advisory
27108

Source: CCN
Type: SECTRACK ID: 1017591
KDE Konqueror Input Validation Hole in Processing HTML Title Tags Permits Cross-Site Scripting Attacks

Source: SECTRACK
Type: UNKNOWN
1017591

Source: CCN
Type: GLSA-200703-10
KHTML: Cross-site scripting (XSS) vulnerability

Source: GENTOO
Type: UNKNOWN
GLSA-200703-10

Source: CCN
Type: KDE Security Advisory 20070206-1
khtml/konqueror title XSS vulnerability

Source: CONFIRM
Type: UNKNOWN
http://www.kde.org/info/security/advisory-20070206-1.txt

Source: CCN
Type: Konqueror Web site
Konqueror - Web Browser, File Manager - and more!

Source: MANDRIVA
Type: UNKNOWN
MDKSA-2007:031

Source: MANDRIVA
Type: UNKNOWN
MDKSA-2007:157

Source: SUSE
Type: UNKNOWN
SUSE-SR:2007:006

Source: CCN
Type: OSVDB ID: 32975
KDE Konqueror KDE HTML library (kdelibs) HTML Parsing XSS

Source: REDHAT
Type: UNKNOWN
RHSA-2007:0909

Source: BUGTRAQ
Type: UNKNOWN
20070124 Re: Safari Improperly Parses HTML Documents & BlogSpot XSS vulnerability

Source: BID
Type: UNKNOWN
22428

Source: CCN
Type: BID-22428
KDE Konqueror KHTML Library Title Cross Site Scripting Vulnerability

Source: CCN
Type: TLSA-2007-19
KHTML vulnerability

Source: CCN
Type: USN-420-1
KDE library vulnerability

Source: UBUNTU
Type: UNKNOWN
USN-420-1

Source: VUPEN
Type: Vendor Advisory
ADV-2007-0505

Source: XF
Type: UNKNOWN
konqueror-html-xss(31935)

Source: CONFIRM
Type: UNKNOWN
https://issues.rpath.com/browse/RPL-1117

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:10244

Source: SUSE
Type: SUSE-SR:2007:006
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/a:kde:konqueror:3.5.5:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:4:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:*

  • Configuration RedHat 6:
  • cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*

  • Configuration RedHat 7:
  • cpe:/o:redhat:enterprise_linux:5::client:*:*:*:*:*

  • Configuration RedHat 8:
  • cpe:/o:redhat:enterprise_linux:5::client_workstation:*:*:*:*:*

  • Configuration RedHat 9:
  • cpe:/o:redhat:enterprise_linux:5::server:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:kde:konqueror:3.5.5:*:*:*:*:*:*:*
  • AND
  • cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4::as:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4::desktop:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4::es:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4::ws:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu:6.06::lts:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007::x86_64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0::x86_64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:3.0::x86_64:*:*:*:*:*
  • OR cpe:/o:kde:kde:3.5.6:*:*:*:*:*:*:*
  • OR cpe:/o:turbolinux:turbolinux:fuji:*:*:*:*:*:*:*
  • OR cpe:/o:turbolinux:turbolinux:*:*:home:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:5:*:client_workstation:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007.1:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:5:*:client:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2007.1::x86-64:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4.5.z::as:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:4.5.z::es:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20070537
    V
    CVE-2007-0537
    2015-11-16
    oval:org.mitre.oval:def:22442
    P
    ELSA-2007:0909: kdelibs security update (Moderate)
    2014-05-26
    oval:org.mitre.oval:def:10244
    V
    The KDE HTML library (kdelibs), as used by Konqueror 3.5.5, does not properly parse HTML comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within a comment in a title tag, a related issue to CVE-2007-0478.
    2013-04-29
    oval:com.redhat.rhsa:def:20070909
    P
    RHSA-2007:0909: kdelibs security update (Moderate)
    2008-03-20
    BACK
    kde konqueror 3.5.5
    kde konqueror 3.5.5
    gentoo linux *
    mandrakesoft mandrake linux corporate server 3.0
    redhat enterprise linux 4
    redhat enterprise linux 4
    redhat enterprise linux 4
    redhat enterprise linux 4
    canonical ubuntu 6.06
    mandrakesoft mandrake linux 2007
    mandrakesoft mandrake linux 2007
    mandrakesoft mandrake linux corporate server 4.0
    mandrakesoft mandrake linux corporate server 4.0
    mandrakesoft mandrake linux corporate server 3.0
    kde kde 3.5.6
    turbolinux turbolinux fuji
    turbolinux turbolinux home *
    redhat enterprise linux 5
    redhat enterprise linux 5
    mandrakesoft mandrake linux 2007.1
    redhat enterprise linux 5
    mandrakesoft mandrake linux 2007.1
    redhat enterprise linux 4.5.z
    redhat enterprise linux 4.5.z