Kde Kio-Extras vulnerabilities
3 known vulnerabilities affecting kde/kio-extras.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1LOW1
Vulnerabilities
Page 1 of 1
CVE-2018-19120P3HIGHCVSS 7.5≥ 0, < 4:18.08.3-12018-11-29
CVE-2018-19120 [HIGH] CVE-2018-19120: The HTML thumbnailer plugin in KDE Applications before 18
The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leading to disclosure of the source IP address.
osv
CVE-2014-8600P4MEDIUMCVSS 4.3≤ 5.1.12014-12-08
CVE-2014-8600 [MEDIUM] CWE-79 CVE-2014-8600: Multiple cross-site scripting (XSS) vulnerabilities in KDE-Runtime 4.14.3 and earlier, kwebkitpart 1
Multiple cross-site scripting (XSS) vulnerabilities in KDE-Runtime 4.14.3 and earlier, kwebkitpart 1.3.4 and earlier, and kio-extras 5.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via a crafted URI using the (1) zip, (2) trash, (3) tar, (4) thumbnail, (5) smtps, (6) smtp, (7) smb, (8) remote, (9) recentdocuments, (10) n
nvd
CVE-2020-12755P4LOWCVSS 3.3≤ 20.04.02020-05-09
CVE-2020-12755 [LOW] CVE-2020-12755: fishProtocol::establishConnection in fish/fish.cpp in KDE kio-extras through 20.04.0 makes a cacheAu
fishProtocol::establishConnection in fish/fish.cpp in KDE kio-extras through 20.04.0 makes a cacheAuthentication call even if the user had not set the keepPassword option. This may lead to unintended KWallet storage of a password.
nvdosv