Known Vulnerabilities for Kmail by Kde
Listed below are 10 of the newest known vulnerabilities associated with "Kmail" by "Kde".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-38373 | In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server r... | 5.3 - MEDIUM | 2021-08-10 | 2021-08-20 |
| CVE-2020-15954 | KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption i... | 6.5 - MEDIUM | 2020-07-27 | 2020-07-30 |
| CVE-2020-11880 | An issue was discovered in KDE KMail before 19.12.3. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a ... | 6.5 - MEDIUM | 2020-04-17 | 2020-04-29 |
| CVE-2019-10732 | In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted m... | 4.3 - MEDIUM | 2019-04-07 | 2022-04-05 |
| CVE-2017-17689 | The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintex... | 5.9 - MEDIUM | 2018-05-16 | 2019-10-03 |
| CVE-2017-9604 | KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a p... | 7.5 - HIGH | 2017-06-13 | 2019-10-03 |
| CVE-2016-7968 | KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized f... | 6.5 - MEDIUM | 2016-12-23 | 2016-12-27 |
| CVE-2016-7967 | KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in... | 8.1 - HIGH | 2016-12-23 | 2016-12-27 |
| CVE-2016-7966 | Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due... | 7.3 - HIGH | 2016-12-23 | 2023-11-07 |
| CVE-2014-8878 | KDE KMail does not encrypt attachments in emails when "automatic encryption" is enabled, which allows remote attackers to obt... | 5.9 - MEDIUM | 2017-09-28 | 2017-10-06 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Kde | Kmail | 5.3.0 | All | All | All |
| Application | Kde | Kmail | 5.2.3 | All | All | All |
| Application | Kde | Kmail | 4.4.0 | All | All | All |
| Application | Kde | Kmail | 4.11.5 | All | All | All |
| Application | Kde | Kmail | 19.12.3 | All | All | All |
| Application | Kde | Kmail | 16.11.90 | All | All | All |
| Application | Kde | Kmail | 16.11.80 | All | All | All |