CVE-2018-19120: Kde Applications
High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.
The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leading to disclosure of the source IP address.
Affected products
- Kde Kde Applications: before 18.12.0 (fixed in 18.12.0)
Published 2018-11-29. Last modified 2026-06-17.