Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-7968

Опубликовано: 23 дек. 2016
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 6.5

Описание

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and included code was executed.

РелизСтатусПримечание
devel

DNE

esm-apps/xenial

not-affected

esm-infra-legacy/trusty

not-affected

4:4.13.3-0ubuntu0.1
precise

not-affected

4:4.8.5-0ubuntu0.1
precise/esm

DNE

precise was not-affected [4:4.8.5-0ubuntu0.1]
trusty

not-affected

4:4.13.3-0ubuntu0.1
trusty/esm

not-affected

4:4.13.3-0ubuntu0.1
upstream

needs-triage

vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

Показывать по

РелизСтатусПримечание
devel

released

4:16.12.3-0ubuntu1
esm-infra-legacy/trusty

DNE

precise

DNE

precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

needs-triage

vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

xenial

DNE

Показывать по

EPSS

Процентиль: 47%
0.0024
Низкий

7.5 High

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
redhat
больше 9 лет назад

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and included code was executed.

CVSS3: 6.5
nvd
около 9 лет назад

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and included code was executed.

CVSS3: 6.5
debian
около 9 лет назад

KMail since version 5.3.0 used a QWebEngine based viewer that had Java ...

CVSS3: 6.5
github
больше 3 лет назад

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and included code was executed.

EPSS

Процентиль: 47%
0.0024
Низкий

7.5 High

CVSS2

6.5 Medium

CVSS3