Kde / Kmail
11 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-50624 | ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled mail server because cleartext HTTP is us… | MEDIUM | 5.9 | Oct 27, 2024 |
| CVE-2021-38373 | kmail: STARTTLS is ignored when "Server requires authentication" not checked in UI | MEDIUM | 6.5 | Aug 10, 2021 |
| CVE-2020-15954 | KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use. | MEDIUM | 6.5 | Jul 27, 2020 |
| CVE-2020-11880 | An issue was discovered in KDE KMail before 19.12.3. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto… | MEDIUM | 6.5 | Apr 17, 2020 |
| CVE-2019-10732 | In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part… | MEDIUM | 4.3 | Apr 7, 2019 |
| CVE-2017-17689 | S/MIME: CBC gadget attacks allows to exfiltrate plaintext out of encrypted emails | MEDIUM | 5.9 | May 16, 2018 |
| CVE-2014-8878 | kdepim: KMail attachments are not encrypted when "automatic encryption" is selected | MEDIUM | 5.9 | Sep 27, 2017 |
| CVE-2017-9604 | kmail: Send Later with Delay bypasses OpenPGP | HIGH | 7.5 | Jun 13, 2017 |
| CVE-2016-7968 | kdepim: JavaScript execution in HTML Mails | MEDIUM | 6.5 | Dec 23, 2016 |
| CVE-2016-7967 | kdepim: JavaScript access to local and remote URLs in Kmail | HIGH | 8.1 | Dec 23, 2016 |
| CVE-2016-7966 | kdepim: HTML injection in plain text viewer of KMail | HIGH | 7.3 | Dec 23, 2016 |
Showing 1 to 11 of 11 CVEs