Kde Applications vulnerabilities
3 known vulnerabilities affecting kde/kde_applications.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2018-19120P3HIGHCVSS 7.5fixed in 18.12.02018-11-29
CVE-2018-19120 [HIGH] CWE-200 CVE-2018-19120: The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound
The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leading to disclosure of the source IP address.
nvd
CVE-2013-7252P4MEDIUMCVSS 5.0≤ 14.11.32015-01-18
CVE-2013-7252 [MEDIUM] CWE-310 CVE-2013-7252: kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode
kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes it easier for attackers to guess passwords via a codebook attack.
nvd
CVE-2018-19516P4MEDIUMCVSS 5.3fixed in 18.122020-03-12
CVE-2018-19516 [MEDIUM] CWE-20 CVE-2018-19516: messagepartthemes/default/defaultrenderer.cpp in messagelib in KDE Applications before 18.12.0 does
messagepartthemes/default/defaultrenderer.cpp in messagelib in KDE Applications before 18.12.0 does not properly restrict the handling of an http-equiv="REFRESH" value.
nvd