cbcvebase.
CVE-2008-1109
published 2008-06-04

CVE-2008-1109: Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attackers to execute arbitrary code via a long DESCRIPTION property in an iCalendar…

PriorityP344critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.75%
92.2th percentile
Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attackers to execute arbitrary code via a long DESCRIPTION property in an iCalendar attachment, which is not properly handled during a reply in the calendar view (aka the Calendars window).

Affected

6 ranges
VendorProductVersion rangeFixed in
debianevolution< evolution 2.22.2-1.1 (bookworm)evolution 2.22.2-1.1 (bookworm)
gnomeevolution
gnomeevolution>= 0 < 2.22.2-1.12.22.2-1.1
gnomeevolution>= 0 < 2.22.2-1.12.22.2-1.1
gnomeevolution>= 0 < 2.22.2-1.12.22.2-1.1
gnomeevolution>= 0 < 2.22.2-1.12.22.2-1.1

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3LOW
vendor_redhat9.3CRITICAL
vendor_ubuntu7.6HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.