cbcvebase.

Gnome Evolution vulnerabilities

28 known vulnerabilities affecting gnome/evolution.

Total CVEs
28
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH5MEDIUM16LOW3

Vulnerabilities

Page 2 of 2
CVE-2006-0040P4MEDIUMCVSS 5.0v2.4.2.12006-03-10
CVE-2006-0040 [MEDIUM] CVE-2006-0040: GNOME Evolution 2.4.2.1 and earlier allows remote attackers to cause a denial of service (CPU and me GNOME Evolution 2.4.2.1 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a text e-mail with a large number of URLs, possibly due to unknown problems in gtkhtml.
nvdosv
CVE-2002-1765P4MEDIUMCVSS 5.0≥ 0, < 1.0.52002-12-31
CVE-2002-1765 [MEDIUM] CVE-2002-1765: Evolution 1 Evolution 1.0.3 and 1.0.4 allows remote attackers to cause a denial of service (memory consumption and crash) via an email with a malformed MIME header.
osv
CVE-2003-0133P4MEDIUMCVSS 5.0≥ 0, < 1.2.42003-05-05
CVE-2003-0133 [MEDIUM] CVE-2003-0133: GtkHTML, as included in Evolution before 1 GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages.
osv
CVE-2002-1471P4MEDIUMCVSS 5.0≥ 0, < 1.2.0-12003-04-22
CVE-2002-1471 [MEDIUM] CVE-2002-1471: The camel component for Ximian Evolution 1 The camel component for Ximian Evolution 1.0.x and earlier does not verify certificates when it establishes a new SSL connection after previously verifying a certificate, which could allow remote attackers to monitor or modify sessions via a man-in-the-middle attack.
osv
CVE-2005-0806P4MEDIUMCVSS 5.0≥ 0, < 2.0.4-22005-05-02
CVE-2005-0806 [MEDIUM] CVE-2005-0806: Evolution 2 Evolution 2.0.3 allows remote attackers to cause a denial of service (application crash or hang) via crafted messages, possibly involving charsets in attachment filenames.
osv
CVE-2006-2789P4LOWCVSS 2.6v2.3.1v2.3.2+6 more2006-06-02
CVE-2006-2789 [LOW] CVE-2006-2789: Evolution 2.2.x and 2.3.x in GNOME 2.7 and 2.8, when "load images if sender in addressbook" is enabl Evolution 2.2.x and 2.3.x in GNOME 2.7 and 2.8, when "load images if sender in addressbook" is enabled, allows remote attackers to cause a denial of service (persistent crash) via a crafted "From" header that triggers an assert error in camel-internet-address.c when a null pointer is used.
nvdosv
CVE-2021-3349P4LOWCVSS 3.3≤ 3.38.32021-02-01
CVE-2021-3349 [LOW] CWE-345 CVE-2021-3349: GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a p GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information from the GnuPG API. NOTE: third parties dispute the significance of this issue, and dispute whether Evolution is the best place to change this behavior
nvd
CVE-2009-1631P4LOWCVSS 2.1≤ 2.26.1v1.0.8+17 more2009-05-14
CVE-2009-1631 [LOW] CWE-264 CVE-2009-1631: The Mailer component in Evolution 2.26.1 and earlier uses world-readable permissions for the .evolut The Mailer component in Evolution 2.26.1 and earlier uses world-readable permissions for the .evolution directory, and certain directories and files under .evolution/ related to local mail, which allows local users to obtain sensitive information by reading these files.
nvdosv
Gnome Evolution vulnerabilities | cvebase