Vulnerability Details CVE-2018-19516
messagepartthemes/default/defaultrenderer.cpp in messagelib in KDE Applications before 18.12.0 does not properly restrict the handling of an http-equiv="REFRESH" value.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 57.7%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2018-19516
-
cpe:2.3:a:kde:kde_applications:14.11.3
-
cpe:2.3:a:kde:kde_applications:14.12
-
cpe:2.3:a:kde:kde_applications:15.04
-
cpe:2.3:a:kde:kde_applications:15.08
-
cpe:2.3:a:kde:kde_applications:15.12
-
cpe:2.3:a:kde:kde_applications:16.04
-
cpe:2.3:a:kde:kde_applications:16.08
-
cpe:2.3:a:kde:kde_applications:16.12
-
cpe:2.3:a:kde:kde_applications:17.04
-
cpe:2.3:a:kde:kde_applications:17.08
-
cpe:2.3:a:kde:kde_applications:17.12
-
cpe:2.3:a:kde:kde_applications:18.04
-
cpe:2.3:a:kde:kde_applications:18.08