CVE List

Id CVE No. Status Description Phase Votes Comments Actions
94786  CVE-2016-7966  Candidate  Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail"s plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is possible to include an HTML comment indicator to hide content.  Assigned (20160909)  None (candidate not yet proposed)    View
94787  CVE-2016-7967  Candidate  KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to remote and local URLs was enabled.  Assigned (20160909)  None (candidate not yet proposed)    View
94788  CVE-2016-7968  Candidate  KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and included code was executed.  Assigned (20160909)  None (candidate not yet proposed)    View
94789  CVE-2016-7969  Candidate  The wrap_lines_smart function in ass_render.c in libass before 0.13.4 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, related to "0/3 line wrapping equalization."  Assigned (20160909)  None (candidate not yet proposed)    View
94790  CVE-2016-7970  Candidate  Buffer overflow in the calc_coeff function in libass/ass_blur.c in libass before 0.13.4 allows remote attackers to cause a denial of service via unspecified vectors.  Assigned (20160909)  None (candidate not yet proposed)    View

Page 18958 of 20943, showing 5 records out of 104715 total, starting on record 94786, ending on 94790

Actions