<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – KDE Plasma</title>
  <link>https://cvedaily.com/pages/tags/kde-plasma.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/kde-plasma.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – KDE Plasma</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:07 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2024-36041 – KSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36041</guid>
    <pubDate>Fri, 05 Jul 2024 02:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-36041</strong></p>
  <p>KSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6.x before 6.0.5.1 allows connections via ICE based purely on the host, i.e., all local connections are accepted. This allows another user on the same machine to gain access to the session manager, e.g., use the session-restore feature to execute arbitrary code as the victim (on the next boot) via earlier use of the /tm…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36041">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-26911 – In the Linux kernel, the following vulnerability has been resolved:

drm/buddy: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-26911</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-26911</guid>
    <pubDate>Wed, 17 Apr 2024 16:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-26911</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/buddy: Fix alloc_range() error handling code  Few users have observed display corruption when they boot the machine to KDE Plasma or playing games. We have root caused the problem that whenever alloc_range() couldn't find the required memory blocks the function was returning SUCCESS in some of the corner cases.  The right ap…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-26911">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-1433 – A vulnerability, which was classified as problematic, was found in KDE Plasma Wo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1433</guid>
    <pubDate>Sun, 11 Feb 2024 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-1433</strong></p>
  <p>A vulnerability, which was classified as problematic, was found in KDE Plasma Workspace up to 5.93.0. This affects the function EventPluginsManager::enabledPlugins of the file components/calendar/eventpluginsmanager.cpp of the component Theme File Handler. The manipulation of the argument pluginId leads to path traversal. It is possible to initiate the attack remotely. The complexity of an attack…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-2213 – The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addon...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2213</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2213</guid>
    <pubDate>Tue, 11 Feb 2020 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-2213</strong></p>
  <p>The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addons uses the GNU C Library rand function's linear congruential generator, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the generator output.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2213">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-2120 – The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2120</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2120</guid>
    <pubDate>Tue, 11 Feb 2020 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-2120</strong></p>
  <p>The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a brute-force attack.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2120">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-6791 – An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma W...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6791</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6791</guid>
    <pubDate>Wed, 07 Feb 2018 02:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-6791</strong></p>
  <p>An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its volume label is plugged in and mounted through the device notifier, it's interpreted as a shell command, leading to a possibility of arbitrary command execution. An example of an offending volume label is "$(touch b)" -- this will create a f…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6791">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-6790 – An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notif...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6790</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6790</guid>
    <pubDate>Wed, 07 Feb 2018 02:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-6790</strong></p>
  <p>An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the src attribute of an IMG element.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6790">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
