KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and included code was executed.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-7968.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "5.3.0" } ] } ]