cbcvebase.

Debian Evolution vulnerabilities

23 known vulnerabilities affecting debian/evolution.

Total CVEs
23
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM12LOW7

Vulnerabilities

Page 1 of 2
CVE-2003-0128P4MEDIUMCVSS 5.0PoCfixed in evolution 1.2.3 (bookworm)2003
CVE-2003-0128 [MEDIUM] CVE-2003-0128: evolution - The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agen... The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly triggering a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 1.2.3) bullseye: resolved (fixed in 1
debian
CVE-2008-1109P3LOWCVSS 9.3fixed in evolution 2.22.2-1.1 (bookworm)2008
CVE-2008-1109 [CRITICAL] CVE-2008-1109: evolution - Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attac... Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attackers to execute arbitrary code via a long DESCRIPTION property in an iCalendar attachment, which is not properly handled during a reply in the calendar view (aka the Calendars window). Scope: local bookworm: resolved (fixed in 2.22.2-1.1) bullseye: resolved (fixed in 2.22.2-1.1) fork
debian
CVE-2006-0528P4LOWCVSS 5.0PoCfixed in evolution 2.2.3-4 (bookworm)2006
CVE-2006-0528 [MEDIUM] CVE-2006-0528: evolution - The cairo library (libcairo), as used in GNOME Evolution and possibly other prod... The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains "Content-Disposition: inline" in the header, and a very long line in the body, which causes the client to repeatedly crash until the e-mail message is manually r
debian
CVE-2003-0130P4MEDIUMCVSS 5.0PoCfixed in evolution 1.2.3 (bookworm)2003
CVE-2003-0130 [MEDIUM] CVE-2003-0130: evolution - The handle_image function in mail-format.c for Ximian Evolution Mail User Agent ... The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers to inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded image. Scope: local bookworm: resolved (fixed in 1.2.3) bullseye: resolved (fixed in 1.2.3) forky: resolved (fixed
debian
CVE-2008-1108P3LOWCVSS 7.6fixed in evolution 2.22.2-1.1 (bookworm)2008
CVE-2008-1108 [HIGH] CVE-2008-1108: evolution - Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled,... Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled, allows remote attackers to execute arbitrary code via a long timezone string in an iCalendar attachment. Scope: local bookworm: resolved (fixed in 2.22.2-1.1) bullseye: resolved (fixed in 2.22.2-1.1) forky: resolved (fixed in 2.22.2-1.1) sid: resolved (fixed in 2.22.2-1.1) trixie: resol
debian
CVE-2003-0129P4MEDIUMCVSS 5.0PoCfixed in evolution 1.2.3 (bookworm)2003
CVE-2003-0129 [MEDIUM] CVE-2003-0129: evolution - Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to ca... Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that is uuencoded multiple times. Scope: local bookworm: resolved (fixed in 1.2.3) bullseye: resolved (fixed in 1.2.3) forky: resolved (fixed in 1.2.3) sid: resolved (fixed in 1.2.3) trixie: resolved (fixed in 1.2.3)
debian
CVE-2008-0072P3MEDIUMCVSS 6.8fixed in evolution 2.12.3-1.1 (bookworm)2008
CVE-2008-0072 [MEDIUM] CVE-2008-0072: evolution - Format string vulnerability in the emf_multipart_encrypted function in mail/em-f... Format string vulnerability in the emf_multipart_encrypted function in mail/em-format.c in Evolution 2.12.3 and earlier allows remote attackers to execute arbitrary code via a crafted encrypted message, as demonstrated using the Version field. Scope: local bookworm: resolved (fixed in 2.12.3-1.1) bullseye: resolved (fixed in 2.12.3-1.1) forky: resolved (fixed in 2
debian
CVE-2007-3257P3MEDIUMCVSS 6.8fixed in evolution 2.12.0-1 (bookworm)2007
CVE-2007-3257 [MEDIUM] CVE-2007-3257: evolution - Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.... Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE value in GData, which is used as an array index. Scope: local bookworm: resolved (fixed in 2.12.0-1) bullseye: resolved (fixed in 2.12.0-1) forky: resolved (fixed in 2.12.0-1) sid: resolved (fixed in 2.12.0
debian
CVE-2018-15587P4MEDIUMCVSS 6.5fixed in evolution 3.30.5-1.1 (bookworm)2018
CVE-2018-15587 [MEDIUM] CVE-2018-15587: evolution - GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for ... GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a valid signature from the entity to be impersonated as an attachment. Scope: local bookworm: resolved (fixed in 3.30.5-1.1) bullseye: resolved (fixed in 3.30.5-1.1) forky: resolved (fixed in 3.30.5-1.1) sid: resolved (
debian
CVE-2005-0102P4CRITICALCVSS 9.8fixed in evolution 2.0.3-1.2 (bookworm)2005
CVE-2005-0102 [CRITICAL] CVE-2005-0102: evolution - Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows loca... Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow. Scope: local bookworm: resolved (fixed in 2.0.3-1.2) bullseye: resolved (fixed in 2.0.3-1.2) forky: resolved (fixed in 2.0.
debian
CVE-2020-11879P4MEDIUMCVSS 6.5fixed in evolution 3.36.0-1 (bookworm)2020
CVE-2020-11879 [MEDIUM] CVE-2020-11879: evolution - An issue was discovered in GNOME Evolution before 3.35.91. By using the propriet... An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make Evolution attach local files or directories to a composed email message without showing a warning to the user, as demonstrated by an attach=. value. Scope: local bookworm: resolved (
debian
CVE-2017-17689P4LOWCVSS 5.9fixed in kf5-messagelib 4:18.08.1-1 (bookworm)2017
CVE-2017-17689 [MEDIUM] CVE-2017-17689: evolution - The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadge... The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2005-2549P4HIGHCVSS 7.5fixed in evolution 2.2.3-3 (bookworm)2005
CVE-2005-2549 [HIGH] CVE-2005-2549: evolution - Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow re... Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers. Scope: local bookworm: resolved (fixed in 2.2.3-3) bullseye: resolved (fixed in 2.2.3-3)
debian
CVE-2005-2550P4HIGHCVSS 7.5fixed in evolution 2.2.3-3 (bookworm)2005
CVE-2005-2550 [HIGH] CVE-2005-2550: evolution - Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attac... Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entries such as task lists, which are not properly handled when the user selects the Calendars tab. Scope: local bookworm: resolved (fixed in 2.2.3-3) bullseye: resolved (fixed in 2.2.3-3) fork
debian
CVE-2007-1002P4MEDIUMCVSS 6.8fixed in evolution 2.10.2-1 (bookworm)2007
CVE-2007-1002 [MEDIUM] CVE-2007-1002: evolution - Format string vulnerability in the write_html function in calendar/gui/e-cal-com... Format string vulnerability in the write_html function in calendar/gui/e-cal-component-memo-preview.c in Evolution Shared Memo 2.8.2.1, and possibly earlier versions, allows user-assisted remote attackers to execute arbitrary code via format specifiers in the categories of a crafted shared memo. Scope: local bookworm: resolved (fixed in 2.10.2-1) bullseye: resolve
debian
CVE-2003-0296P4HIGHCVSS 7.5fixed in evolution 1.3.2 (bookworm)2003
CVE-2003-0296 [HIGH] CVE-2003-0296: evolution - The IMAP Client for Evolution 1.2.4 allows remote malicious IMAP servers to caus... The IMAP Client for Evolution 1.2.4 allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large literal size values that cause either integer signedness errors or integer overflow errors. Scope: local bookworm: resolved (fixed in 1.3.2) bullseye: resolved (fixed in 1.3.2) forky: resolved (fixed in 1.3.2) si
debian
CVE-2006-0040P4LOWCVSS 5.0fixed in evolution 2.10.1 (bookworm)2006
CVE-2006-0040 [MEDIUM] CVE-2006-0040: evolution - GNOME Evolution 2.4.2.1 and earlier allows remote attackers to cause a denial of... GNOME Evolution 2.4.2.1 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a text e-mail with a large number of URLs, possibly due to unknown problems in gtkhtml. Scope: local bookworm: resolved (fixed in 2.10.1) bullseye: resolved (fixed in 2.10.1) forky: resolved (fixed in 2.10.1) sid: resolved (fixed in 2.10.1) tri
debian
CVE-2002-1765P4MEDIUMCVSS 5.0fixed in evolution 1.0.5 (bookworm)2002
CVE-2002-1765 [MEDIUM] CVE-2002-1765: evolution - Evolution 1.0.3 and 1.0.4 allows remote attackers to cause a denial of service (... Evolution 1.0.3 and 1.0.4 allows remote attackers to cause a denial of service (memory consumption and crash) via an email with a malformed MIME header. Scope: local bookworm: resolved (fixed in 1.0.5) bullseye: resolved (fixed in 1.0.5) forky: resolved (fixed in 1.0.5) sid: resolved (fixed in 1.0.5) trixie: resolved (fixed in 1.0.5)
debian
CVE-2003-0133P4MEDIUMCVSS 5.0fixed in evolution 1.2.4 (bookworm)2003
CVE-2003-0133 [MEDIUM] CVE-2003-0133: evolution - GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause... GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages. Scope: local bookworm: resolved (fixed in 1.2.4) bullseye: resolved (fixed in 1.2.4) forky: resolved (fixed in 1.2.4) sid: resolved (fixed in 1.2.4) trixie: resolved (fixed in 1.2.4)
debian
CVE-2002-1471P4MEDIUMCVSS 5.0fixed in evolution 1.2.0-1 (bookworm)2002
CVE-2002-1471 [MEDIUM] CVE-2002-1471: evolution - The camel component for Ximian Evolution 1.0.x and earlier does not verify certi... The camel component for Ximian Evolution 1.0.x and earlier does not verify certificates when it establishes a new SSL connection after previously verifying a certificate, which could allow remote attackers to monitor or modify sessions via a man-in-the-middle attack. Scope: local bookworm: resolved (fixed in 1.2.0-1) bullseye: resolved (fixed in 1.2.0-1) forky: re
debian
Debian Evolution vulnerabilities | cvebase