{"api_version":"1","generated_at":"2026-07-23T05:22:09+00:00","cve":"CVE-2005-0237","urls":{"html":"https://cve.report/CVE-2005-0237","api":"https://cve.report/api/cve/CVE-2005-0237.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-0237","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-0237"},"summary":{"title":"CVE-2005-0237","description":"The International Domain Name (IDN) support in Konqueror 3.2.1 on KDE 3.2.1 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.","state":"PUBLISHED","assigner":"redhat","published_at":"2005-05-02 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19236","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19236","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.shmoo.com/idn","name":"http://www.shmoo.com/idn","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"404 Not Found","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2005:058","name":"http://www.mandriva.com/security/advisories?name=MDKSA-2005:058","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Advisories - Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2005-325.html","name":"http://www.redhat.com/support/errata/RHSA-2005-325.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.shmoo.com/idn/homograph.txt","name":"http://www.shmoo.com/idn/homograph.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"404 Not Found","mime":"text/plain","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/12461","name":"http://www.securityfocus.com/bid/12461","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Multiple Web Browser International Domain Name Handling Site Property Spoofing Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html","name":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"[Full-Disclosure] state of homograph attacks","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10671","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10671","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031460.html","name":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031460.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"[Full-Disclosure] state of homograph attacks","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.kde.org/info/security/advisory-20050316-2.txt","name":"http://www.kde.org/info/security/advisory-20050316-2.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/427976/100/0/threaded","name":"http://www.securityfocus.com/archive/1/427976/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/14162","name":"http://secunia.com/advisories/14162","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Secunia - Advisories - KDE Applications IDN Spoofing Security Issue","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-0237","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-0237","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"237","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"kde","cpe5":"kde","cpe6":"3.2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"237","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"kde","cpe5":"konqueror","cpe6":"3.2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T21:05:25.300Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.shmoo.com/idn/homograph.txt"},{"name":"multiple-browsers-idn-spoof(19236)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19236"},{"name":"20050206 state of homograph attacks","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.kde.org/info/security/advisory-20050316-2.txt"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.shmoo.com/idn"},{"name":"20050206 Re: state of homograph attacks","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031460.html"},{"name":"FLSA:178606","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"http://www.securityfocus.com/archive/1/427976/100/0/threaded"},{"name":"MDKSA-2005:058","tags":["vendor-advisory","x_refsource_MANDRAKE","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2005:058"},{"name":"14162","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/14162"},{"name":"RHSA-2005:325","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2005-325.html"},{"name":"oval:org.mitre.oval:def:10671","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10671"},{"name":"12461","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/12461"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-02-06T00:00:00.000Z","descriptions":[{"lang":"en","value":"The International Domain Name (IDN) support in Konqueror 3.2.1 on KDE 3.2.1 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-19T14:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.shmoo.com/idn/homograph.txt"},{"name":"multiple-browsers-idn-spoof(19236)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/19236"},{"name":"20050206 state of homograph attacks","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.kde.org/info/security/advisory-20050316-2.txt"},{"tags":["x_refsource_MISC"],"url":"http://www.shmoo.com/idn"},{"name":"20050206 Re: state of homograph attacks","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031460.html"},{"name":"FLSA:178606","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"http://www.securityfocus.com/archive/1/427976/100/0/threaded"},{"name":"MDKSA-2005:058","tags":["vendor-advisory","x_refsource_MANDRAKE"],"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2005:058"},{"name":"14162","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/14162"},{"name":"RHSA-2005:325","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2005-325.html"},{"name":"oval:org.mitre.oval:def:10671","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10671"},{"name":"12461","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/12461"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2005-0237","datePublished":"2005-02-07T05:00:00.000Z","dateReserved":"2005-02-07T00:00:00.000Z","dateUpdated":"2024-08-07T21:05:25.300Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-05-02 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:kde:konqueror:3.2.1:*:*:*:*:*:*:*","matchCriteriaId":"0172B167-5780-4F80-ACC9-2FB8B60D6717"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:kde:kde:3.2.1:*:*:*:*:*:*:*","matchCriteriaId":"ACEE0AED-7918-41E9-A902-AC4070E03132"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"237","Ordinal":"1","Title":"CVE-2005-0237","CVE":"CVE-2005-0237","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"237","Ordinal":"1","NoteData":"The International Domain Name (IDN) support in Konqueror 3.2.1 on KDE 3.2.1 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.","Type":"Description","Title":"CVE-2005-0237"},{"CveYear":"2005","CveId":"237","Ordinal":"2","NoteData":"2005-02-07","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"237","Ordinal":"3","NoteData":"2018-10-19","Type":"Other","Title":"Modified"}]}}}