CVE-2013-2074: Kde Kdelibs
Medium severity, CVSS 5.0. EPSS: 2% chance of exploitation in the next 30 days.
kioslave/http/http.cpp in KIO in kdelibs 4.10.3 and earlier allows attackers to discover credentials via a crafted request that triggers an "internal server error," which includes the username and password in an error message.
Affected products
- Kde Kdelibs: up to and including 4.10.3; version 4.10.0 only; version 4.10.1 only; version 4.10.2 only
Published 2014-02-05. Last modified 2026-06-16.