Lucene search

K
cveMitreCVE-2006-7139
HistoryMar 07, 2007 - 8:19 p.m.

CVE-2006-7139

2007-03-0720:19:00
CWE-20
mitre
web.nvd.nist.gov
32
kmail
kde
denial of service
cve-2006-7139
nvd

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:N/A:P

AI Score

6.8

Confidence

High

EPSS

0.032

Percentile

91.3%

Kmail 1.9.1 on KDE 3.5.2, with “Prefer HTML to Plain Text” enabled, allows remote attackers to cause a denial of service (crash) via an HTML e-mail with certain table and frameset tags that trigger a segmentation fault, possibly involving invalid free or delete operations.

Affected configurations

Nvd
Node
kdekdeMatch3.5.2
AND
kdek-mailMatch1.9.1
VendorProductVersionCPE
kdekde3.5.2cpe:2.3:o:kde:kde:3.5.2:*:*:*:*:*:*:*
kdek-mail1.9.1cpe:2.3:a:kde:k-mail:1.9.1:*:*:*:*:*:*:*

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:N/A:P

AI Score

6.8

Confidence

High

EPSS

0.032

Percentile

91.3%