Skip to main content

Vendor/product archive

gnome / evolution CVEs

Beta · best-effort

22 CVEs tagged to gnome / evolution5 Critical, 5 High, 9 Medium, 3 Low, 0 Unrated.

CVE-2009-3721

Published May 26, 2021

Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3349

Published Feb 1, 2021

GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information fr…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-11879

Published Apr 17, 2020

An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can ma…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-15587

Published Feb 11, 2019

GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a valid signature from the entity…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10727

Published Jul 20, 2018

camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wis…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-12422

Published Jun 15, 2018

addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger a Buffer Overflow via a long query that…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-17689

Published May 16, 2018

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2009-1631

Published May 14, 2009

The Mailer component in Evolution 2.26.1 and earlier uses world-readable permissions for the .evolution directory, and certain directories and files under .evolution/ related to l…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-1108

Published Jun 4, 2008

Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled, allows remote attackers to execute arbitrary code via a long timezone string in an iCalendar attac…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1109

Published Jun 4, 2008

Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attackers to execute arbitrary code via a long DESCRIPTION property in an iCalendar attachment, which is…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0072

Published Mar 6, 2008

Format string vulnerability in the emf_multipart_encrypted function in mail/em-format.c in Evolution 2.12.3 and earlier allows remote attackers to execute arbitrary code via a cra…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3257

Published Jun 19, 2007

Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE value in GData, whi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1266

Published Mar 6, 2007

Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between signed and unsigned p…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2789

Published Jun 2, 2006

Evolution 2.2.x and 2.3.x in GNOME 2.7 and 2.8, when "load images if sender in addressbook" is enabled, allows remote attackers to cause a denial of service (persistent crash) via…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-0040

Published Mar 10, 2006

GNOME Evolution 2.4.2.1 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a text e-mail with a large number of URLs, possibly due t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0528

Published Feb 2, 2006

The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attache…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2549

Published Aug 12, 2005

Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) ful…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2550

Published Aug 12, 2005

Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0102

Published Jan 24, 2005

Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-22 of 22 CVEsPage 1 of 1