Vulnerabilities > KDE > Kmail

DATE CVE VULNERABILITY TITLE RISK
2020-07-27 CVE-2020-15954 Cleartext Transmission of Sensitive Information vulnerability in multiple products
KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use.
network
kde debian CWE-319
4.3
2020-04-17 CVE-2020-11880 Unspecified vulnerability in KDE Kmail
An issue was discovered in KDE KMail before 19.12.3.
network
low complexity
kde
6.4
2019-04-07 CVE-2019-10732 Cleartext Transmission of Sensitive Information vulnerability in multiple products
In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email.
network
kde debian CWE-319
4.3
2018-05-16 CVE-2017-17689 The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. 4.3
2017-09-28 CVE-2014-8878 Cryptographic Issues vulnerability in KDE Kmail 4.11.5
KDE KMail does not encrypt attachments in emails when "automatic encryption" is enabled, which allows remote attackers to obtain sensitive information by sniffing the network.
network
kde CWE-310
4.3
2017-06-13 CVE-2017-9604 Missing Encryption of Sensitive Data vulnerability in KDE Kmail and Messagelib
KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the network.
network
low complexity
kde CWE-311
5.0
2016-12-23 CVE-2016-7968 Code Injection vulnerability in KDE Kmail 4.4.0/5.2.3/5.3.0
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled.
network
low complexity
kde CWE-94
7.5
2016-12-23 CVE-2016-7967 Improper Access Control vulnerability in KDE Kmail 4.4.0/5.2.3/5.3.0
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled.
network
kde CWE-284
5.8
2016-12-23 CVE-2016-7966 Code Injection vulnerability in multiple products
Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer.
network
low complexity
kde debian fedoraproject suse CWE-94
7.3