CVE-2016-7967

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to remote and local URLs was enabled.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kde:kmail:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2016-12-23 22:59

Updated : 2024-02-28 15:44


NVD link : CVE-2016-7967

Mitre link : CVE-2016-7967

CVE.ORG link : CVE-2016-7967


JSON object : View

Products Affected

kde

  • kmail
CWE
CWE-284

Improper Access Control

CWE-94

Improper Control of Generation of Code ('Code Injection')