Vulnerability index

Browse CVEs

99 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kcoreaddons HIGH 7.8
CVE-2026-41526

In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing d…

Fix: 6.25.0+
Fix from $1,950 2026-04-28
Plasma Workspace HIGH 7.8
CVE-2024-36041

KSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6.x before 6.0.5.1 allows connections via ICE based purely on the host,…

Fix: 5.27.11.1 / 6.0.5.1+
Fix from $1,950 2024-07-05
Kcron HIGH 7.8
CVE-2022-24986

KDE KCron through 21.12.2 uses a temporary file in /tmp when saving, but reuses the filename during an editing session. Thus, someone watching it be …

Fix: after 21.12.2
Fix from $1,950 2022-02-26
Kate HIGH 7.8
CVE-2022-23853

The LSP (Language Server Protocol) plugin in KDE Kate before 21.12.2 and KTextEditor before 5.91.0 tries to execute the associated LSP server binary …

Fix: 5.91.0 / 21.12.2+
Fix from $1,950 2022-02-11
Kmail MEDIUM 5.3
CVE-2021-38373

In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" …

Mitigation only
Fix from $1,600 2021-08-10
Kimageformats MEDIUM 5.5
CVE-2021-36083

KDE KImageFormats 5.70.0 through 5.81.0 has a stack-based buffer overflow in XCFImageFormat::loadTileRLE.

Fix: after 5.81.0
Fix from $1,600 2021-07-01
Messagelib MEDIUM 6.5
CVE-2021-31855

KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a decrypted encrypted message sto…

Fix: after 5.17.0
Fix from $1,600 2021-06-02
Discover HIGH 7.5
CVE-2021-28117

libdiscover/backends/KNSBackend/KNSResource.cpp in KDE Discover before 5.21.3 automatically creates links to potentially dangerous URLs (that are nei…

Fix: 5.21.3+
Fix from $1,950 2021-03-20
Partition Manager HIGH 7.8
CVE-2020-27187

An issue was discovered in KDE Partition Manager 4.1.0 before 4.2.0. The kpmcore_externalcommand helper contains a logic flaw in which the service in…

Fix: 4.2.0+
Fix from $1,950 2020-10-26
Kdeconnect MEDIUM 5.5
CVE-2020-26164

In kdeconnect-kde (aka KDE Connect) before 20.08.2, an attacker on the local network could send crafted packets that trigger use of large amounts of …

Fix: 20.08.2+
Fix from $1,600 2020-10-07
Amarok MEDIUM 5.5
CVE-2020-13152

A remote user can create a specially crafted M3U file, media playlist file that when loaded by the target user, will trigger a memory leak, whereby A…

No fix yet
Fix from $1,600 2020-05-20
Kmail MEDIUM 6.5
CVE-2020-11880

An issue was discovered in KDE KMail before 19.12.3. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source…

Fix: 19.12.3+
Fix from $1,600 2020-04-17
Kde Applications MEDIUM 5.3
CVE-2018-19516

messagepartthemes/default/defaultrenderer.cpp in messagelib in KDE Applications before 18.12.0 does not properly restrict the handling of an http-equ…

Fix: 18.12+
Fix from $1,600 2020-03-12
Paste Applet HIGH 8.4
CVE-2013-2120

The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, …

Fix: 4.10.5+
Fix from $1,950 2020-02-11
Paste Applet MEDIUM 5.5
CVE-2013-2213

The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addons uses the GNU C Library rand function's linear congruential generato…

No fix yet
Fix from $1,600 2020-02-11
Kde Applications HIGH 7.5
CVE-2018-19120

The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leadin…

Fix: 18.12.0+
Fix from $1,950 2018-11-29
Ktexteditor HIGH 7.8
CVE-2018-10361

An issue was discovered in KTextEditor 5.34.0 through 5.45.0. Insecure handling of temporary files in the KTextEditor's kauth_ktexteditor_helper serv…

Fix: after 5.45.0
Fix from $1,950 2018-04-25
Plasma Workspace MEDIUM 5.3
CVE-2018-6790

An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover …

Fix: 5.12.0+
Fix from $1,600 2018-02-07
Kmail MEDIUM 5.9
CVE-2014-8878

KDE KMail does not encrypt attachments in emails when "automatic encryption" is enabled, which allows remote attackers to obtain sensitive informatio…

Patch available
Fix from $1,600 2017-09-28
Kmail HIGH 7.5
CVE-2017-9604

KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt act…

Fix: after 5.5.1
Fix from $1,950 2017-06-13
Kauth HIGH 7.8
CVE-2017-8422

KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper …

Fix: after 5.33
Fix from $1,950 2017-05-17
Kdelibs MEDIUM 5.5
CVE-2017-6410

kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including…

Fix: after 5.31
Fix from $1,600 2017-03-02
Kmail HIGH 8.1
CVE-2016-7967

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security…

Fix: after 5.3.0
Fix from $1,950 2016-12-23
Kmail MEDIUM 6.5
CVE-2016-7968

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and includ…

Fix: after 5.3.0
Fix from $1,600 2016-12-23
Kde Applications MEDIUM 5.0
CVE-2013-7252

kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes i…

Fix: after 14.11.3
Fix from $1,600 2015-01-18
Plasma Desktop HIGH 7.2
CVE-2014-8651

The KDE Clock KCM policykit helper in kde-workspace before 4.11.14 and plasma-desktop before 5.1.1 allows local users to gain privileges via a crafte…

Fix: after 5.1
Fix from $1,950 2014-12-06
Kdelibs MEDIUM 5.0
CVE-2013-2074

kioslave/http/http.cpp in KIO in kdelibs 4.10.3 and earlier allows attackers to discover credentials via a crafted request that triggers an "internal…

Fix: after 4.10.3
Fix from $1,600 2014-02-05
Kde Workspace MEDIUM 5.0
CVE-2013-4132

KDE-Workspace 4.10.5 and earlier does not properly handle the return value of the glibc 2.17 crypt and pw_encrypt functions, which allows remote atta…

Fix: after 4.10.5
Fix from $1,600 2013-09-16
Kde MEDIUM 6.8
CVE-2012-4515EPSS 6%

Use-after-free vulnerability in khtml/rendering/render_replaced.cpp in Konqueror in KDE 4.7.3, when the context menu is shown, allows remote attacker…

No fix yet
Fix from $1,600 2012-11-11
Kde MEDIUM 6.4
CVE-2012-4513EPSS 13%

khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via l…

No fix yet
Fix from $1,600 2012-11-11