Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The HTMLQuoteColorer::process function in messageviewer/htmlquotecolorer.cpp in KDE PIM 4.6 through 4.8 does not disable JavaScript, Java, and Plugins, which allows remote attackers to inject arbitrary web script or HTML via a crafted email.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
KDE PIM 安全限制绕过漏洞
Vulnerability Description
kdepim是KDE的个人信息管理程序套件,帮助用户管理EMAIL,任务和联系人等信息。 KDE PIM 4.6至4.8版本中的messageviewer/htmlquotecolorer.cpp中的HTMLQuoteColorer::process函数中存在漏洞,该漏洞源于未禁用JavaScript,Java,Plugins。远程攻击者可利用该漏洞借助特制的邮件注入任意web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A