Search CVE reports
11 – 20 of 36 results
CVE-2018-12422
Medium priority** DISPUTED ** addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger a Buffer Overflow via a long query that is processed by the strcat...
2 affected packages
evolution, evolution-data-server
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
evolution | — | — | — | Ignored | Ignored |
evolution-data-server | — | — | — | Ignored | Ignored |
CVE-2017-17689
Medium prioritySome fixes available 17 of 33
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
3 affected packages
evolution, kmail, thunderbird
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
evolution | Not affected | Not affected | Not affected | Not affected | Not affected |
kmail | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |
thunderbird | Fixed | Fixed | Fixed | Fixed | Fixed |
CVE-2014-1639
Medium prioritysyncevo/installcheck-local.sh in syncevolution before 1.3.99.7 uses mktemp to create a safe temporary file but appends a suffix to the original filename and writes to this new filename, which allows local users to overwrite...
1 affected packages
syncevolution
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
syncevolution | — | — | — | Not affected | Not affected |
CVE-2013-4166
Medium prioritySome fixes available 3 of 4
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause...
1 affected packages
evolution-data-server
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
evolution-data-server | — | — | — | — | — |
CVE-2011-3201
Low priorityGNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter to a mailto: URL, which attaches the file to the email.
1 affected packages
evolution
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
evolution | — | — | — | — | Not affected |
CVE-2012-1177
Medium prioritySome fixes available 4 of 6
libgdata before 0.10.2 and 0.11.x before 0.11.1 does not validate SSL certificates, which allows remote attackers to obtain user names and passwords via a man-in-the-middle (MITM) attack with a spoofed certificate.
2 affected packages
evolution-data-server, libgdata
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
evolution-data-server | — | — | — | — | — |
libgdata | — | — | — | — | — |
CVE-2011-3709
Low priorityb2evolution 3.3.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by locales/ru_RU/ru-RU.locale.php and certain...
1 affected packages
b2evolution
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
b2evolution | — | — | — | — | — |
CVE-2009-1631
Low priorityThe Mailer component in Evolution 2.26.1 and earlier uses world-readable permissions for the .evolution directory, and certain directories and files under .evolution/ related to local mail, which allows local users to...
1 affected packages
evolution
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
evolution | — | — | — | — | — |
CVE-2009-0587
Medium priorityMultiple integer overflows in Evolution Data Server (aka evolution-data-server) before 2.24.5 allow context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation in (1)...
1 affected packages
evolution-data-server
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
evolution-data-server | — | — | — | — | — |
CVE-2009-0582
Low priorityThe ntlm_challenge function in the NTLM SASL authentication mechanism in camel/camel-sasl-ntlm.c in Camel in Evolution Data Server (aka evolution-data-server) 2.24.5 and earlier, and 2.25.92 and earlier 2.25.x versions, does not...
1 affected packages
evolution-data-server
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
evolution-data-server | — | — | — | — | — |