5
CVSSv2

CVE-2018-19120

Published: 29/11/2018 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The HTML thumbnailer plugin in KDE Applications prior to 18.12.0 allows malicious users to trigger outbound TCP connections to arbitrary IP addresses, leading to disclosure of the source IP address.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kde kde applications

Vendor Advisories

Debian Bug report logs - #913595 CVE-2018-19120: kio-extras: HTML Thumbnailer automatic remote file access Package: kio-extras; Maintainer for kio-extras is Debian/Kubuntu Qt/KDE Maintainers <debian-qt-kde@listsdebianorg>; Source for kio-extras is src:kio-extras (PTS, buildd, popcon) Reported by: Martin Steigerwald <Mar ...