4.3
CVSSv2

CVE-2012-3413

Published: 07/08/2012 Updated: 08/08/2012
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The HTMLQuoteColorer::process function in messageviewer/htmlquotecolorer.cpp in KDE PIM 4.6 up to and including 4.8 does not disable JavaScript, Java, and Plugins, which allows remote malicious users to inject arbitrary web script or HTML via a crafted email.

Vulnerable Product Search on Vulmon Subscribe to Product

kde kde pim 4.6

kde kde pim 4.8

Vendor Advisories

KDE PIM could be made to execute JavaScript if it opened a specially crafted email ...