CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
94786 | CVE-2016-7966 | Candidate | Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail"s plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is possible to include an HTML comment indicator to hide content. | Assigned (20160909) | None (candidate not yet proposed) | View | |
94787 | CVE-2016-7967 | Candidate | KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to remote and local URLs was enabled. | Assigned (20160909) | None (candidate not yet proposed) | View | |
94788 | CVE-2016-7968 | Candidate | KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and included code was executed. | Assigned (20160909) | None (candidate not yet proposed) | View | |
94789 | CVE-2016-7969 | Candidate | The wrap_lines_smart function in ass_render.c in libass before 0.13.4 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, related to "0/3 line wrapping equalization." | Assigned (20160909) | None (candidate not yet proposed) | View | |
94790 | CVE-2016-7970 | Candidate | Buffer overflow in the calc_coeff function in libass/ass_blur.c in libass before 0.13.4 allows remote attackers to cause a denial of service via unspecified vectors. | Assigned (20160909) | None (candidate not yet proposed) | View |
Page 18958 of 20943, showing 5 records out of 104715 total, starting on record 94786, ending on 94790