Логотип exploitDog
bind:CVE-2021-31855
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-31855

Количество 5

Количество 5

ubuntu логотип

CVE-2021-31855

больше 4 лет назад

KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g., an IMAP server) causes KMail to upload the decrypted content of the message to the remote server. With a crafted message, a user could be tricked into decrypting an encrypted message and then deleting an attachment attached to this message. If the attacker has access to the messages stored on the email server, then the attacker could read the decrypted content of the encrypted message. This occurs in ViewerPrivate::deleteAttachment in messageviewer/src/viewer/viewer_p.cpp.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-31855

больше 4 лет назад

KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g., an IMAP server) causes KMail to upload the decrypted content of the message to the remote server. With a crafted message, a user could be tricked into decrypting an encrypted message and then deleting an attachment attached to this message. If the attacker has access to the messages stored on the email server, then the attacker could read the decrypted content of the encrypted message. This occurs in ViewerPrivate::deleteAttachment in messageviewer/src/viewer/viewer_p.cpp.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-31855

больше 4 лет назад

KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-h76g-vp43-8cw5

больше 3 лет назад

KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g., an IMAP server) causes KMail to upload the decrypted content of the message to the remote server. With a crafted message, a user could be tricked into decrypting an encrypted message and then deleting an attachment attached to this message. If the attacker has access to the messages stored on the email server, then the attacker could read the decrypted content of the encrypted message. This occurs in ViewerPrivate::deleteAttachment in messageviewer/src/viewer/viewer_p.cpp.

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2021-04687

почти 5 лет назад

Уязвимость функции ViewerPrivate::deleteAttachment компонента messageviewer/src/viewer/viewer_p.cpp средства отображения сообщений Messagelib, связанная с отсутствием защиты передаваемых данных, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-31855

KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g., an IMAP server) causes KMail to upload the decrypted content of the message to the remote server. With a crafted message, a user could be tricked into decrypting an encrypted message and then deleting an attachment attached to this message. If the attacker has access to the messages stored on the email server, then the attacker could read the decrypted content of the encrypted message. This occurs in ViewerPrivate::deleteAttachment in messageviewer/src/viewer/viewer_p.cpp.

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-31855

KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g., an IMAP server) causes KMail to upload the decrypted content of the message to the remote server. With a crafted message, a user could be tricked into decrypting an encrypted message and then deleting an attachment attached to this message. If the attacker has access to the messages stored on the email server, then the attacker could read the decrypted content of the encrypted message. This occurs in ViewerPrivate::deleteAttachment in messageviewer/src/viewer/viewer_p.cpp.

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-31855

KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages ...

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-h76g-vp43-8cw5

KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g., an IMAP server) causes KMail to upload the decrypted content of the message to the remote server. With a crafted message, a user could be tricked into decrypting an encrypted message and then deleting an attachment attached to this message. If the attacker has access to the messages stored on the email server, then the attacker could read the decrypted content of the encrypted message. This occurs in ViewerPrivate::deleteAttachment in messageviewer/src/viewer/viewer_p.cpp.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2021-04687

Уязвимость функции ViewerPrivate::deleteAttachment компонента messageviewer/src/viewer/viewer_p.cpp средства отображения сообщений Messagelib, связанная с отсутствием защиты передаваемых данных, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 6.5
0%
Низкий
почти 5 лет назад

Уязвимостей на страницу