Back

CVE-2002-1224

Directory traversal vulnerability in kpf for KDE 3.0.1 through KDE 3.0.3a allows remote attackers to read arbitrary files as the kpf user via a URL with a modified icon parameter.

Published: Oct 28, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (4)

Vendor Product Version
kde kde 3.0.1
kde kde 3.0.2
kde kde 3.0.3
kde kde 3.0.3a

GitHub Security Advisory GHSA-cj8x-fpwc-j8jq

Directory traversal vulnerability in kpf for KDE 3.0.1 through KDE 3.0.3a allows remote attackers...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 8.84%

Top 5% most likely to be exploited

Threat Score 22.7 / 100

Data Sources

NVD EPSS GitHub