CVE-2013-2074: Kde Kdelibs

Medium severity, CVSS 5.0. EPSS: 2% chance of exploitation in the next 30 days.

kioslave/http/http.cpp in KIO in kdelibs 4.10.3 and earlier allows attackers to discover credentials via a crafted request that triggers an "internal server error," which includes the username and password in an error message.

Affected products

  • Kde Kdelibs: up to and including 4.10.3; version 4.10.0 only; version 4.10.1 only; version 4.10.2 only

Published 2014-02-05. Last modified 2026-06-16.