CVE-2006-7139

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
07/03/2007
Last modified:
09/04/2025

Description

Kmail 1.9.1 on KDE 3.5.2, with "Prefer HTML to Plain Text" enabled, allows remote attackers to cause a denial of service (crash) via an HTML e-mail with certain table and frameset tags that trigger a segmentation fault, possibly involving invalid free or delete operations.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:kde:kde:3.5.2:*:*:*:*:*:*:*
cpe:2.3:a:kde:k-mail:1.9.1:*:*:*:*:*:*:*