VYPR
High severity8.1NVD Advisory· Published Dec 23, 2016· Updated May 6, 2026

CVE-2016-7967

CVE-2016-7967

Description

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to remote and local URLs was enabled.

Affected products

1
  • cpe:2.3:a:kde:kmail:*:*:*:*:*:*:*:*
    Range: <=5.3.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.