Vulnerabilities > KDE

DATE CVE VULNERABILITY TITLE RISK
2017-07-25 CVE-2015-7543 Race Condition vulnerability in multiple products
aRts 1.5.10 and kdelibs3 3.5.10 and earlier do not properly create temporary directories, which allows local users to hijack the IPC by pre-creating the temporary directory.
4.4
2017-06-13 CVE-2017-9604 Missing Encryption of Sensitive Data vulnerability in KDE Kmail and Messagelib
KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the network.
network
low complexity
kde CWE-311
5.0
2017-05-17 CVE-2017-8422 Authentication Bypass by Spoofing vulnerability in KDE Kauth and Kdelibs
KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.
local
low complexity
kde CWE-290
7.2
2017-03-27 CVE-2017-5330 OS Command Injection vulnerability in multiple products
ark before 16.12.1 might allow remote attackers to execute arbitrary code via an executable in an archive, related to associated applications.
local
low complexity
fedoraproject kde CWE-78
7.8
2017-03-02 CVE-2017-6410 Cleartext Transmission of Sensitive Information vulnerability in KDE Kdelibs and KIO
kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.
network
kde CWE-319
4.3
2016-12-23 CVE-2016-7968 Code Injection vulnerability in KDE Kmail 4.4.0/5.2.3/5.3.0
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled.
network
low complexity
kde CWE-94
7.5
2016-12-23 CVE-2016-7967 Improper Access Control vulnerability in KDE Kmail 4.4.0/5.2.3/5.3.0
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled.
network
kde CWE-284
5.8
2016-12-23 CVE-2016-7966 Code Injection vulnerability in multiple products
Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer.
network
low complexity
kde debian fedoraproject suse CWE-94
7.3
2016-12-23 CVE-2016-7787 Code Injection vulnerability in multiple products
A maliciously crafted command line for kdesu can result in the user only seeing part of the commands that will actually get executed as super user.
network
low complexity
kde opensuse CWE-94
4.0
2016-12-23 CVE-2016-2312 7PK - Security Features vulnerability in multiple products
Turning all screens off in Plasma-workspace and kscreenlocker while the lock screen is shown can result in the screen being unlocked when turning a screen on again.
local
low complexity
kde fedoraproject opensuse CWE-254
4.6