4.3
CVSSv2

CVE-2014-8878

Published: 28/09/2017 Updated: 06/10/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

KDE KMail does not encrypt attachments in emails when "automatic encryption" is enabled, which allows remote malicious users to obtain sensitive information by sniffing the network.

Vulnerable Product Search on Vulmon Subscribe to Product

kde kmail 4.11.5

Vendor Advisories

Debian Bug report logs - #791800 kmail: CVE-2014-8878: Attachments are not encrypted when "automatic encryption" is selected" Package: kmail; Maintainer for kmail is Debian/Kubuntu Qt/KDE Maintainers <debian-qt-kde@listsdebianorg>; Source for kmail is src:kmail (PTS, buildd, popcon) Reported by: Daniel Hornung <danielh ...
KDE KMail does not encrypt attachments in emails when "automatic encryption" is enabled, which allows remote attackers to obtain sensitive information by sniffing the network ...