Skip to main content

Vendor archive

kde CVEs

Beta · best-effort

187 CVEs tagged to vendor kde13 Critical, 67 High, 93 Medium, 14 Low, 0 Unrated.

CVE-2026-41526

Published Apr 28, 2026

In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle meta…

CVSS 6.5 · Medium
evidence mentions
6
Buzz score
39.5
Vendor/product tagsBeta · best-effort

CVE-2024-36041

Published Jul 5, 2024

KSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6.x before 6.0.5.1 allows connections via ICE based purely on the host, i.e., all local connections a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1433

Published Feb 11, 2024

A vulnerability, which was classified as problematic, was found in KDE Plasma Workspace up to 5.93.0. This affects the function EventPluginsManager::enabledPlugins of the file com…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-24986

Published Feb 26, 2022

KDE KCron through 21.12.2 uses a temporary file in /tmp when saving, but reuses the filename during an editing session. Thus, someone watching it be created the first time could p…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23853

Published Feb 11, 2022

The LSP (Language Server Protocol) plugin in KDE Kate before 21.12.2 and KTextEditor before 5.91.0 tries to execute the associated LSP server binary when opening a file of a given…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38373

Published Aug 10, 2021

In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38372

Published Aug 10, 2021

In KDE Trojita 0.7, man-in-the-middle attackers can create new folders because untagged responses from an IMAP server are accepted before STARTTLS.

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-36083

Published Jul 1, 2021

KDE KImageFormats 5.70.0 through 5.81.0 has a stack-based buffer overflow in XCFImageFormat::loadTileRLE.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31855

Published Jun 2, 2021

KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g.,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28117

Published Mar 20, 2021

libdiscover/backends/KNSBackend/KNSResource.cpp in KDE Discover before 5.21.3 automatically creates links to potentially dangerous URLs (that are neither https:// nor http://) bas…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27187

Published Oct 26, 2020

An issue was discovered in KDE Partition Manager 4.1.0 before 4.2.0. The kpmcore_externalcommand helper contains a logic flaw in which the service invoking D-Bus is not properly c…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15954

Published Jul 27, 2020

KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13152

Published May 20, 2020

A remote user can create a specially crafted M3U file, media playlist file that when loaded by the target user, will trigger a memory leak, whereby Amarok 2.8.0 continue to waste…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12755

Published May 9, 2020

fishProtocol::establishConnection in fish/fish.cpp in KDE kio-extras through 20.04.0 makes a cacheAuthentication call even if the user had not set the keepPassword option. This ma…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-11880

Published Apr 17, 2020

An issue was discovered in KDE KMail before 19.12.3. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make KMa…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-19516

Published Mar 12, 2020

messagepartthemes/default/defaultrenderer.cpp in messagelib in KDE Applications before 18.12.0 does not properly restrict the handling of an http-equiv="REFRESH" value.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2213

Published Feb 11, 2020

The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addons uses the GNU C Library rand function's linear congruential generator, which makes it easier for c…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2120

Published Feb 11, 2020

The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 187 CVEsPage 1 of 8