RCE via Cross Application Scripting was found in ksysguard. see $URL.
So is this still applicable for 4.4.2 or 4.4.3 ?
ksysguard lets users monitor remote machines using various transports including a custom command. That's a feature, not a bug. Users should of course only open .sgrd files from trusted sources.