Known Vulnerabilities for Kmail by Kde
Listed below are 10 of the newest known vulnerabilities associated with "Kmail" by "Kde".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-38373 json | In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server r... | 5.3 - MEDIUM | 2021-08-10 | 2021-08-20 |
| CVE-2020-15954 json | KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption i... | 6.5 - MEDIUM | 2020-07-27 | 2020-07-30 |
| CVE-2020-11880 json | An issue was discovered in KDE KMail before 19.12.3. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a ... | 6.5 - MEDIUM | 2020-04-17 | 2020-04-29 |
| CVE-2019-10732 json | In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted m... | 4.3 - MEDIUM | 2019-04-07 | 2022-04-05 |
| CVE-2017-17689 json | The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintex... | 5.9 - MEDIUM | 2018-05-16 | 2019-10-03 |
| CVE-2017-9604 json | KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a p... | 7.5 - HIGH | 2017-06-13 | 2019-10-03 |
| CVE-2016-7968 json | KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized f... | 6.5 - MEDIUM | 2016-12-23 | 2016-12-27 |
| CVE-2016-7967 json | KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in... | 8.1 - HIGH | 2016-12-23 | 2016-12-27 |
| CVE-2016-7966 json | Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due... | 7.3 - HIGH | 2016-12-23 | 2023-11-07 |
| CVE-2014-8878 json | KDE KMail does not encrypt attachments in emails when "automatic encryption" is enabled, which allows remote attackers to obt... | 5.9 - MEDIUM | 2017-09-28 | 2017-10-06 |