ZeroHour

CVE-2016-7967

CVSS 3.0
8.1 high
EPSS
2%p79
Published
()
Modified
Description

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to remote and local URLs was enabled.

Vendors
kde
Products
kmail
Weakness
CWE-94, CWE-284
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.