High severity7.3NVD Advisory· Published Dec 23, 2016· Updated May 6, 2026
CVE-2016-7966
CVE-2016-7966
Description
Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is possible to include an HTML comment indicator to hide content.
Affected products
4- cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:25:*:*:*:*:*:*:*
- cpe:2.3:o:suse:linux_enterprise:12.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- lists.opensuse.org/opensuse-updates/2016-10/msg00065.htmlnvdThird Party Advisory
- www.debian.org/security/2016/dsa-3697nvdThird Party Advisory
- www.openwall.com/lists/oss-security/2016/10/05/1nvdThird Party Advisory
- www.securityfocus.com/bid/93360nvdThird Party AdvisoryVDB Entry
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QNMM5TVPTJQFPJ3YDF4DPXDFW3GQLWLY/nvd
News mentions
0No linked articles in our index yet.