K Mail
Vendor:
First CVE: Jun 1, 1999 · Active for 27 years
15
Total CVEs
More Total CVEs than 77% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 7% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact K Mail over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 1, 1999
27 years ago
Most Recent CVE
Aug 10, 2021
1,811 days ago
CVE Severity & Scoring
K Mail15 CVEs
67%
27%
All CVEs352,713 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network10 (66.7%)
Unknown5 (33.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (46.7%)
High3 (20.0%)
Unknown5 (33.3%)
User Interaction
None7 (46.7%)
Unknown5 (33.3%)
Required3 (20.0%)
Privileges Required
Low1 (6.7%)
High0 (0.0%)
None9 (60.0%)
Unknown5 (33.3%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9604HIGH KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Se | Jun 13, 2017 | 7.5 | 26 | NO | NO |
CVE-2016-7967HIGH KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to r | Dec 23, 2016 | 8.1 | 26 | NO | NO |
CVE-2016-7966HIGH Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to i | Dec 23, 2016 | 7.3 | 25 | NO | NO |
CVE-2020-15954MEDIUM KDE KMail 19.12.3 (aka 5.13.3) engages in unencrypted POP3 communication during times when the UI indicates that encryption is in use. | Jul 27, 2020 | 6.5 | 23 | NO | NO |
CVE-2017-17689MEDIUM The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. | May 16, 2018 | 5.9 | 22 | NO | NO |
CVE-2016-7968MEDIUM KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and included code was executed. | Dec 23, 2016 | 6.5 | 22 | NO | NO |
CVE-1999-0735MEDIUM KDE K-Mail allows local users to gain privileges via a symlink attack in temporary user directories. | Jan 4, 2000 | 4.6 | 21 | NO | YES |
CVE-2007-1265HIGH KMail 1.9.5 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents KMail from visually distinguishing between signed and unsigned portions o | Mar 6, 2007 | 7.8 | 20 | NO | NO |
CVE-2021-38373MEDIUM In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked. | Aug 10, 2021 | 5.3 | 18 | NO | NO |
CVE-2019-10732MEDIUM In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hi | Apr 7, 2019 | 4.3 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
13.3% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For K Mail
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.2.3 | 1 | 4.3 | 0.6% | 0 | 0 |
| 4.11.5 | 1 | 5.9 | 1.2% | 0 | 0 |
| 1.95 | 1 | 7.8 | 2.1% | 0 | 0 |
| 1.94 | 1 | 7.8 | 2.1% | 0 | 0 |
| 1.93 | 1 | 7.8 | 2.1% | 0 | 0 |
| 1.92 | 1 | 7.8 | 2.1% | 0 | 0 |
| 19.12.3 | 2 | 5.9 | 0.6% | 0 | 0 |
| 1.9.1 | 2 | 5.2 | 2.5% | 0 | 1 |
| 1.90 | 1 | 7.8 | 2.1% | 0 | 0 |
| 1.89 | 1 | 7.8 | 2.1% | 0 | 0 |
| 1.88 | 1 | 7.8 | 2.1% | 0 | 0 |
| 1.87 | 1 | 7.8 | 2.1% | 0 | 0 |
| 1.86.2.36 | 1 | 7.8 | 2.1% | 0 | 0 |
| 1.7.1 | 1 | 7.8 | 2.1% | 0 | 0 |
| 1.3.1 | 1 | 7.8 | 2.1% | 0 | 0 |
| 1.2 | 2 | 6.4 | 1.9% | 0 | 0 |
| 1.102 | 1 | 7.8 | 2.1% | 0 | 0 |
| 1.101 | 1 | 7.8 | 2.1% | 0 | 0 |
| 1.1 | 1 | 7.8 | 2.1% | 0 | 0 |
| 1.0.29.2 | 1 | 7.8 | 2.1% | 0 | 0 |