Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-0755
http://www.securityfocus.com/bid/13313
http://www.kde.org/info/security/advisory-20050420-1.txt