CVE-2012-3413

Severity CVSS v4.0:
Pending analysis
Type:
CWE-16 Configuration Errors
Publication date:
07/08/2012
Last modified:
11/04/2025

Description

The HTMLQuoteColorer::process function in messageviewer/htmlquotecolorer.cpp in KDE PIM 4.6 through 4.8 does not disable JavaScript, Java, and Plugins, which allows remote attackers to inject arbitrary web script or HTML via a crafted email.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kde:kde_pim:4.6:*:*:*:*:*:*:*
cpe:2.3:a:kde:kde_pim:4.8:*:*:*:*:*:*:*