cbcvebase.
CVE-2009-0587
published 2009-03-14

CVE-2009-0587: Multiple integer overflows in Evolution Data Server (aka evolution-data-server) before 2.24.5 allow context-dependent attackers to execute arbitrary code via a…

PriorityP342high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.31%
87.2th percentile
Multiple integer overflows in Evolution Data Server (aka evolution-data-server) before 2.24.5 allow context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation in (1) addressbook/libebook/e-vcard.c in evc or (2) camel/camel-mime-utils.c in libcamel.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianevolution-data-server< evolution-data-server 2.22.3-1 (bookworm)evolution-data-server 2.22.3-1 (bookworm)
gnomeevolution-data-server>= 0 < 2.22.3-12.22.3-1
gnomeevolution-data-server>= 0 < 2.22.3-12.22.3-1
gnomeevolution-data-server>= 0 < 2.22.3-12.22.3-1
gnomeevolution-data-server>= 0 < 2.22.3-12.22.3-1
go-evolutionevolution-data-server<= 2.24.4

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.