Search CVE reports


Toggle filters

21 – 30 of 36 results


CVE-2009-0547

Low priority
Ignored

Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the...

1 affected package

evolution-data-server

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
evolution-data-server
Show less packages

CVE-2008-1109

High priority
Fixed

Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attackers to execute arbitrary code via a long DESCRIPTION property in an iCalendar attachment, which is not properly handled during a reply in...

1 affected package

evolution

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
evolution
Show less packages

CVE-2008-1108

Medium priority
Fixed

Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled, allows remote attackers to execute arbitrary code via a long timezone string in an iCalendar attachment.

1 affected package

evolution

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
evolution
Show less packages

CVE-2008-0072

High priority
Fixed

Format string vulnerability in the emf_multipart_encrypted function in mail/em-format.c in Evolution 2.12.3 and earlier allows remote attackers to execute arbitrary code via a crafted encrypted message, as demonstrated using the...

1 affected package

evolution

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
evolution
Show less packages

CVE-2007-3257

Unknown priority
Fixed

Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE value in GData, which is used as an array index.

1 affected package

evolution-data-server

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
evolution-data-server
Show less packages

CVE-2007-2358

Unknown priority
Not affected

** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in b2evolution allow remote attackers to execute arbitrary PHP code via a URL in the (1) inc_path parameter to (a) a_noskin.php, (b) a_stub.php, (c) admin.php, (d)...

1 affected package

b2evolution

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
b2evolution
Show less packages

CVE-2007-1002

Unknown priority
Fixed

Format string vulnerability in the write_html function in calendar/gui/e-cal-component-memo-preview.c in Evolution Shared Memo 2.8.2.1, and possibly earlier versions, allows user-assisted remote attackers to execute arbitrary code...

1 affected package

evolution

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
evolution
Show less packages

CVE-2007-1266

Unknown priority
Ignored

Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between signed and unsigned portions of OpenPGP messages with...

1 affected package

evolution

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
evolution
Show less packages

CVE-2007-0175

Unknown priority

Some fixes available 1 of 4

Cross-site scripting (XSS) vulnerability in htsrv/login.php in b2evolution 1.8.6 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes in the redirect_to parameter.

1 affected package

b2evolution

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
b2evolution
Show less packages

CVE-2006-2789

Unknown priority
Not affected

Evolution 2.2.x and 2.3.x in GNOME 2.7 and 2.8, when "load images if sender in addressbook" is enabled, allows remote attackers to cause a denial of service (persistent crash) via a crafted "From" header that triggers an assert...

1 affected package

evolution

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
evolution
Show less packages