CVE-2014-8878

MEDIUM

KDE KMail - Unencrypted Attachment Transmission via Automatic Encryption Feature

Title source: llm
STIX 2.1

Description

KDE KMail does not encrypt attachments in emails when "automatic encryption" is enabled, which allows remote attackers to obtain sensitive information by sniffing the network.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/75986
Issue Tracking, Patch, Vendor Advisory x_refsource_confirm
https://bugs.kde.org/show_bug.cgi?id=340312
Issue Tracking, Patch, Third Party Advisory, VDB Entry x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1243777
Mailing List, Patch, Third Party Advisory, VDB Entry mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/07/16/10

Scores

CVSS v3 5.9
EPSS 0.0028
EPSS Percentile 51.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-310
Status published
Products (1)
kde/kmail 4.11.5
Published Sep 28, 2017
Tracked Since Feb 18, 2026