Vulnerability index

Browse CVEs

99 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2026-41526 In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing d… Kcoreaddons 6.25.0+ Fix from $1,9502026-04-28 HIGH 7.8 CVE-2024-36041 KSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6.x before 6.0.5.1 allows connections via ICE based purely on the host,… Plasma Workspace 5.27.11.1 / 6.0.5.1+ Fix from $1,9502024-07-05 HIGH 7.8 CVE-2022-24986 KDE KCron through 21.12.2 uses a temporary file in /tmp when saving, but reuses the filename during an editing session. Thus, someone watching it be … Kcron after 21.12.2 Fix from $1,9502022-02-26 HIGH 7.8 CVE-2022-23853 The LSP (Language Server Protocol) plugin in KDE Kate before 21.12.2 and KTextEditor before 5.91.0 tries to execute the associated LSP server binary … Kate 5.91.0 / 21.12.2+ Fix from $1,9502022-02-11 MEDIUM 5.3 CVE-2021-38373 In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" … Kmail Mitigation only Fix from $1,6002021-08-10 MEDIUM 5.5 CVE-2021-36083 KDE KImageFormats 5.70.0 through 5.81.0 has a stack-based buffer overflow in XCFImageFormat::loadTileRLE. Kimageformats after 5.81.0 Fix from $1,6002021-07-01 MEDIUM 6.5 CVE-2021-31855 KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a decrypted encrypted message sto… Messagelib after 5.17.0 Fix from $1,6002021-06-02 HIGH 7.5 CVE-2021-28117 libdiscover/backends/KNSBackend/KNSResource.cpp in KDE Discover before 5.21.3 automatically creates links to potentially dangerous URLs (that are nei… Discover 5.21.3+ Fix from $1,9502021-03-20 HIGH 7.8 CVE-2020-27187 An issue was discovered in KDE Partition Manager 4.1.0 before 4.2.0. The kpmcore_externalcommand helper contains a logic flaw in which the service in… Partition Manager 4.2.0+ Fix from $1,9502020-10-26 MEDIUM 5.5 CVE-2020-26164 In kdeconnect-kde (aka KDE Connect) before 20.08.2, an attacker on the local network could send crafted packets that trigger use of large amounts of … Kdeconnect 20.08.2+ Fix from $1,6002020-10-07 MEDIUM 5.5 CVE-2020-13152 A remote user can create a specially crafted M3U file, media playlist file that when loaded by the target user, will trigger a memory leak, whereby A… Amarok No fix yet Fix from $1,6002020-05-20 MEDIUM 6.5 CVE-2020-11880 An issue was discovered in KDE KMail before 19.12.3. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source… Kmail 19.12.3+ Fix from $1,6002020-04-17 MEDIUM 5.3 CVE-2018-19516 messagepartthemes/default/defaultrenderer.cpp in messagelib in KDE Applications before 18.12.0 does not properly restrict the handling of an http-equ… Kde Applications 18.12+ Fix from $1,6002020-03-12 HIGH 8.4 CVE-2013-2120 The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, … Paste Applet 4.10.5+ Fix from $1,9502020-02-11 MEDIUM 5.5 CVE-2013-2213 The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addons uses the GNU C Library rand function's linear congruential generato… Paste Applet No fix yet Fix from $1,6002020-02-11 HIGH 7.5 CVE-2018-19120 The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leadin… Kde Applications 18.12.0+ Fix from $1,9502018-11-29 HIGH 7.8 CVE-2018-10361 An issue was discovered in KTextEditor 5.34.0 through 5.45.0. Insecure handling of temporary files in the KTextEditor's kauth_ktexteditor_helper serv… Ktexteditor after 5.45.0 Fix from $1,9502018-04-25 MEDIUM 5.3 CVE-2018-6790 An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover … Plasma Workspace 5.12.0+ Fix from $1,6002018-02-07 MEDIUM 5.9 CVE-2014-8878 KDE KMail does not encrypt attachments in emails when "automatic encryption" is enabled, which allows remote attackers to obtain sensitive informatio… Kmail Patch available Fix from $1,6002017-09-28 HIGH 7.5 CVE-2017-9604 KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt act… Kmail after 5.5.1 Fix from $1,9502017-06-13 HIGH 7.8 CVE-2017-8422 KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper … Kauth after 5.33 Fix from $1,9502017-05-17 MEDIUM 5.5 CVE-2017-6410 kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including… Kdelibs after 5.31 Fix from $1,6002017-03-02 HIGH 8.1 CVE-2016-7967 KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security… Kmail after 5.3.0 Fix from $1,9502016-12-23 MEDIUM 6.5 CVE-2016-7968 KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and includ… Kmail after 5.3.0 Fix from $1,6002016-12-23 MEDIUM 5.0 CVE-2013-7252 kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes i… Kde Applications after 14.11.3 Fix from $1,6002015-01-18 HIGH 7.2 CVE-2014-8651 The KDE Clock KCM policykit helper in kde-workspace before 4.11.14 and plasma-desktop before 5.1.1 allows local users to gain privileges via a crafte… Plasma Desktop after 5.1 Fix from $1,9502014-12-06 MEDIUM 5.0 CVE-2013-2074 kioslave/http/http.cpp in KIO in kdelibs 4.10.3 and earlier allows attackers to discover credentials via a crafted request that triggers an "internal… Kdelibs after 4.10.3 Fix from $1,6002014-02-05 MEDIUM 5.0 CVE-2013-4132 KDE-Workspace 4.10.5 and earlier does not properly handle the return value of the glibc 2.17 crypt and pw_encrypt functions, which allows remote atta… Kde Workspace after 4.10.5 Fix from $1,6002013-09-16 MEDIUM 6.8 CVE-2012-4515EPSS 6% Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, allows remote attacker… Kde No fix yet Fix from $1,6002012-11-11 MEDIUM 6.4 CVE-2012-4513EPSS 13% khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via l… Kde No fix yet Fix from $1,6002012-11-11