Skip to main content

Vendor/product archive

kde / kmail CVEs

Beta · best-effort

10 CVEs tagged to kde / kmail0 Critical, 3 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2021-38373

Published Aug 10, 2021

In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15954

Published Jul 27, 2020

KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11880

Published Apr 17, 2020

An issue was discovered in KDE KMail before 19.12.3. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make KMa…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-10732

Published Apr 7, 2019

In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be h…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-17689

Published May 16, 2018

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2014-8878

Published Sep 28, 2017

KDE KMail does not encrypt attachments in emails when "automatic encryption" is enabled, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9604

Published Jun 13, 2017

KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the S…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-7968

Published Dec 23, 2016

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and included code was executed.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-7967

Published Dec 23, 2016

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1