CVE-2003-0459: Kde Konqueror

Medium severity, CVSS 5.0. EPSS: 2.9% chance of exploitation in the next 30 days.

KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.

Affected products

  • Kde Konqueror: version 2.1.1 only; version 2.2.2 only; version 3.0 only; version 3.0.1 only; version 3.0.2 only; version 3.0.3 only; …
  • Kde Konqueror Embedded: version 0.1 only
  • Red Hat Analog Real-Time Synthesizer: version 2.1.1-5 only; version 2.2-11 only
  • Red Hat Kdebase: version 3.0.3-13 only
  • Red Hat Kdelibs: version 2.1.1-5 only; version 2.2-11 only; version 3.0.0-10 only; version 3.1-10 only
  • Red Hat Kdelibs Devel: version 2.1.1-5 only; version 2.2-11 only; version 3.0.0-10 only; version 3.0.3-8 only; version 3.1-10 only
  • Red Hat Kdelibs Sound: version 2.1.1-5 only; version 2.2-11 only
  • Red Hat Kdelibs Sound Devel: version 2.1.1-5 only; version 2.2-11 only

Published 2003-08-27. Last modified 2026-06-16.