CVE-2016-7967

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to remote and local URLs was enabled.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kde:kmail:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:58

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2016/10/05/1 - Third Party Advisory () http://www.openwall.com/lists/oss-security/2016/10/05/1 - Third Party Advisory
References () http://www.securityfocus.com/bid/93360 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/93360 - Third Party Advisory, VDB Entry

Information

Published : 2016-12-23 22:59

Updated : 2024-11-21 02:58


NVD link : CVE-2016-7967

Mitre link : CVE-2016-7967

CVE.ORG link : CVE-2016-7967


JSON object : View

Products Affected

kde

  • kmail
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-284

Improper Access Control