CVE-2016-7967

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to remote and local URLs was enabled.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:kde:kmail:*:*:*:*:*:*:*:*

Information

Published : 2016-12-23 14:59

Updated : 2016-12-27 10:42


NVD link : CVE-2016-7967

Mitre link : CVE-2016-7967


JSON object : View

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-284

Improper Access Control

Advertisement

dedicated server usa

Products Affected

kde

  • kmail