Show filters
210 Total Results
Displaying 51-60 of 210
Sort by:
Attacker Value
Unknown
CVE-2015-7543
Disclosure Date: July 25, 2017 (last updated November 26, 2024)
aRts 1.5.10 and kdelibs3 3.5.10 and earlier do not properly create temporary directories, which allows local users to hijack the IPC by pre-creating the temporary directory.
0
Attacker Value
Unknown
CVE-2017-9604
Disclosure Date: June 13, 2017 (last updated November 26, 2024)
KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the network.
0
Attacker Value
Unknown
CVE-2017-8422
Disclosure Date: May 17, 2017 (last updated November 26, 2024)
KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.
0
Attacker Value
Unknown
CVE-2017-5330
Disclosure Date: March 27, 2017 (last updated November 08, 2023)
ark before 16.12.1 might allow remote attackers to execute arbitrary code via an executable in an archive, related to associated applications.
0
Attacker Value
Unknown
CVE-2017-6410
Disclosure Date: March 02, 2017 (last updated November 26, 2024)
kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.
0
Attacker Value
Unknown
CVE-2016-7967
Disclosure Date: December 23, 2016 (last updated November 25, 2024)
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to remote and local URLs was enabled.
0
Attacker Value
Unknown
CVE-2016-2312
Disclosure Date: December 23, 2016 (last updated November 25, 2024)
Turning all screens off in Plasma-workspace and kscreenlocker while the lock screen is shown can result in the screen being unlocked when turning a screen on again.
0
Attacker Value
Unknown
CVE-2016-7787
Disclosure Date: December 23, 2016 (last updated November 25, 2024)
A maliciously crafted command line for kdesu can result in the user only seeing part of the commands that will actually get executed as super user.
0
Attacker Value
Unknown
CVE-2016-7966
Disclosure Date: December 23, 2016 (last updated November 08, 2023)
Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is possible to include an HTML comment indicator to hide content.
0
Attacker Value
Unknown
CVE-2016-7968
Disclosure Date: December 23, 2016 (last updated November 25, 2024)
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and included code was executed.
0