<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – KDE Plasma (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/kde-plasma.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/kde-plasma-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – KDE Plasma (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:07 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2024-36041 – KSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36041</guid>
    <pubDate>Fri, 05 Jul 2024 02:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-36041</strong></p>
  <p>KSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6.x before 6.0.5.1 allows connections via ICE based purely on the host, i.e., all local connections are accepted. This allows another user on the same machine to gain access to the session manager, e.g., use the session-restore feature to execute arbitrary code as the victim (on the next boot) via earlier use of the /tm…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36041">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-2120 – The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2120</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2120</guid>
    <pubDate>Tue, 11 Feb 2020 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-2120</strong></p>
  <p>The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a brute-force attack.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2120">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
