Gnome Evolution vulnerabilities
28 known vulnerabilities affecting gnome/evolution.
Total CVEs
28
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH5MEDIUM16LOW3
Vulnerabilities
Page 1 of 2
CVE-2003-0128P4MEDIUMCVSS 5.0PoC≥ 0, < 1.2.32003-03-24
CVE-2003-0128 [MEDIUM] CVE-2003-0128: The try_uudecoding function in mail-format
The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly triggering a heap-based buffer overflow.
osv
CVE-2016-10727P3CRITICALCVSS 9.8fixed in 3.21.22018-07-20
CVE-2016-10727 [CRITICAL] CWE-200 CVE-2016-10727: camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server bef
camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. The server c
nvd
CVE-2007-1266P4MEDIUMCVSS 5.0PoC≤ 2.8.12007-03-06
CVE-2007-1266 [MEDIUM] CVE-2007-1266: Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, whic
Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.
nvd
CVE-2018-12422P3CRITICALCVSS 9.8≤ 3.29.22018-06-15
CVE-2018-12422 [CRITICAL] CWE-119 CVE-2018-12422: addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through
addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger a Buffer Overflow via a long query that is processed by the strcat function. NOTE: the software maintainer disputes this because "the code had computed the required string length first, and then allocated a lar
nvd
CVE-2008-1109P3CRITICALCVSS 9.3v2.22.12008-06-04
CVE-2008-1109 [CRITICAL] CWE-119 CVE-2008-1109: Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attackers to execute arbi
Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attackers to execute arbitrary code via a long DESCRIPTION property in an iCalendar attachment, which is not properly handled during a reply in the calendar view (aka the Calendars window).
nvdosv
CVE-2006-0528P4MEDIUMCVSS 5.0PoCv2.3.1v2.3.2+6 more2006-02-02
CVE-2006-0528 [MEDIUM] CVE-2006-0528: The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote
The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains "Content-Disposition: inline" in the header, and a very long line in the body, which causes the client to repeatedly crash until the e-mail message is manual
nvdosv
CVE-2003-0130P4MEDIUMCVSS 5.0PoC≥ 0, < 1.2.32003-03-24
CVE-2003-0130 [MEDIUM] CVE-2003-0130: The handle_image function in mail-format
The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers to inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded image.
osv
CVE-2013-4166P3HIGHCVSS 7.5≤ 3.8.4v3.8.4 and earlier2020-02-06
CVE-2013-4166 [HIGH] CWE-200 CVE-2013-4166: The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain sensitive information.
nvd
CVE-2008-1108P3HIGHCVSS 7.6v2.2.12008-06-04
CVE-2008-1108 [HIGH] CWE-119 CVE-2008-1108: Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled, allows remote attac
Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled, allows remote attackers to execute arbitrary code via a long timezone string in an iCalendar attachment.
nvdosv
CVE-2003-0129P4MEDIUMCVSS 5.0PoC≥ 0, < 1.2.32003-03-24
CVE-2003-0129 [MEDIUM] CVE-2003-0129: Ximian Evolution Mail User Agent 1
Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that is uuencoded multiple times.
osv
CVE-2008-0072P3MEDIUMCVSS 6.8≤ 2.12.32008-03-06
CVE-2008-0072 [MEDIUM] CWE-134 CVE-2008-0072: Format string vulnerability in the emf_multipart_encrypted function in mail/em-format.c in Evolution
Format string vulnerability in the emf_multipart_encrypted function in mail/em-format.c in Evolution 2.12.3 and earlier allows remote attackers to execute arbitrary code via a crafted encrypted message, as demonstrated using the Version field.
nvdosv
CVE-2007-3257P3MEDIUMCVSS 6.8v1.112007-06-19
CVE-2007-3257 [MEDIUM] CVE-2007-3257: Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMA
Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE value in GData, which is used as an array index.
nvdosv
CVE-2018-15587P4MEDIUMCVSS 6.5≤ 3.28.22019-02-11
CVE-2018-15587 [MEDIUM] CWE-347 CVE-2018-15587: GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages u
GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a valid signature from the entity to be impersonated as an attachment.
nvdosv
CVE-2005-0102P4CRITICALCVSS 9.8≤ 2.0.22005-01-24
CVE-2005-0102 [CRITICAL] CWE-190 CVE-2005-0102: Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote ma
Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow.
nvdosv
CVE-2020-11879P4MEDIUMCVSS 6.5fixed in 3.35.912020-04-17
CVE-2020-11879 [MEDIUM] CVE-2020-11879: An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "m
An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make Evolution attach local files or directories to a composed email message without showing a warning to the user, as demonstrated by an attach=. value.
nvdosv
CVE-2005-2549P4HIGHCVSS 7.5v1.5v2.0+8 more2005-08-12
CVE-2005-2549 [HIGH] CVE-2005-2549: Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to ca
Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers.
nvdosv
CVE-2005-2550P4HIGHCVSS 7.5v1.4v1.5+9 more2005-08-12
CVE-2005-2550 [HIGH] CVE-2005-2550: Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a deni
Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entries such as task lists, which are not properly handled when the user selects the Calendars tab.
nvdosv
CVE-2007-1002P4MEDIUMCVSS 6.8≥ 0, < 2.10.2-12007-03-21
CVE-2007-1002 [MEDIUM] CVE-2007-1002: Format string vulnerability in the write_html function in calendar/gui/e-cal-component-memo-preview
Format string vulnerability in the write_html function in calendar/gui/e-cal-component-memo-preview.c in Evolution Shared Memo 2.8.2.1, and possibly earlier versions, allows user-assisted remote attackers to execute arbitrary code via format specifiers in the categories of a crafted shared memo.
osv
CVE-2003-0296P4HIGHCVSS 7.5≥ 0, < 1.3.22003-06-16
CVE-2003-0296 [HIGH] CVE-2003-0296: The IMAP Client for Evolution 1
The IMAP Client for Evolution 1.2.4 allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large literal size values that cause either integer signedness errors or integer overflow errors.
osv
CVE-2011-3201P4MEDIUMCVSS 4.3≤ 3.0.3v1.0.8+43 more2013-03-08
CVE-2011-3201 [MEDIUM] CWE-200 CVE-2011-3201: GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the a
GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter to a mailto: URL, which attaches the file to the email.
nvd
1 / 2Next →