KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to remote and local URLs was enabled.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2016-12-23T22:00:00

Updated: 2024-08-06T02:13:21.600Z

Reserved: 2016-09-09T00:00:00

Link: CVE-2016-7967

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2016-12-23T22:59:00.267

Modified: 2016-12-27T18:42:57.117

Link: CVE-2016-7967

cve-icon Redhat

Severity : Moderate

Publid Date: 2016-10-04T00:00:00Z

Links: CVE-2016-7967 - Bugzilla