Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown
CVE-2016-7968
Disclosure Date: December 23, 2016 (last updated November 25, 2024)
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and included code was executed.
0
Attacker Value
Unknown
CVE-2009-3124
Disclosure Date: September 09, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in get_message.cgi in QuarkMail allows remote attackers to read arbitrary files via a .. (dot dot) in the tf parameter.
0
Attacker Value
Unknown
CVE-2006-7111
Disclosure Date: March 05, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Futomi's CGI Cafe KMail CGI 1.0.3 and earlier allows remote attackers to bypass authentication and obtain unauthorized email access via unspecified vectors.
0
Attacker Value
Unknown
CVE-2006-7062
Disclosure Date: February 24, 2007 (last updated October 04, 2023)
calendar.php in Kamgaing Email System (kmail) 2.3 and earlier allows remote attackers to obtain the full path of the server via an invalid d parameter, which leaks the path in an error message.
0
Attacker Value
Unknown
CVE-2006-2104
Disclosure Date: April 29, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Kamgaing Email System (kmail) 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) d parameter to main.php, ordner parameter to (2) main.php, or (3) webdisk.php, (4) draft parameter to compose.php, or (5) m, or (6) y parameter to calendar.php.
0
Attacker Value
Unknown
CVE-2005-0404
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
KMail 1.7.1 in KDE 3.3.2 allows remote attackers to spoof email information, such as whether the email has been digitally signed or encrypted, via HTML formatted email.
0
Attacker Value
Unknown
CVE-2004-2677
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Format string vulnerability in qwik-smtpd.c in QwikMail SMTP (qwik-smtpd) 0.3 and earlier allows remote attackers to execute arbitrary code via format specifiers in the (1) clientRcptTo array, and the (2) Received and (3) messageID variables, possibly involving HELO and hostname arguments.
0
Attacker Value
Unknown
CVE-2002-1193
Disclosure Date: October 28, 2002 (last updated February 22, 2025)
tkmail before 4.0beta9-8.1 allows local users to create or overwrite files as users via a symlink attack on temporary files.
0