CVE-2006-7139
Kmail 1.9.1 on KDE 3.5.2, with "Prefer HTML to Plain Text" enabled, allows remote attackers to cause a denial of service (crash) via an HTML e-mail with certain table and frameset tags that trigger a segmentation fault, possibly involving invalid free or delete operations.
- Affected products
- Kmail
- Kde K-mail
- = 1.9.1
- Fix
- Available
- CVSS 2.0
- 2.6 LOW
- EPSS
- 3.0% (86th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2007-03-07
CVE-2006-7139 at NVD
1 known exploit for CVE-2006-7139
Proof-of-concept code and exploit modules indexed by Sploitus