Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

21 – 30 of 36 results


CVE-2009-0547

Low priority
Ignored

Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the...

1 affected packages

evolution-data-server

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
evolution-data-server
Show less packages

CVE-2008-1109

High priority
Fixed

Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attackers to execute arbitrary code via a long DESCRIPTION property in an iCalendar attachment, which is not properly handled during a reply in...

1 affected packages

evolution

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
evolution
Show less packages

CVE-2008-1108

Medium priority
Fixed

Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled, allows remote attackers to execute arbitrary code via a long timezone string in an iCalendar attachment.

1 affected packages

evolution

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
evolution
Show less packages

CVE-2008-0072

High priority
Fixed

Format string vulnerability in the emf_multipart_encrypted function in mail/em-format.c in Evolution 2.12.3 and earlier allows remote attackers to execute arbitrary code via a crafted encrypted message, as demonstrated using the...

1 affected packages

evolution

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
evolution
Show less packages

CVE-2007-3257

Unknown priority
Fixed

Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE value in GData, which is used as an array index.

1 affected packages

evolution-data-server

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
evolution-data-server
Show less packages

CVE-2007-2358

Unknown priority
Not affected

** DISPUTED ** Multiple PHP remote file inclusion vulnerabilities in b2evolution allow remote attackers to execute arbitrary PHP code via a URL in the (1) inc_path parameter to (a) a_noskin.php, (b) a_stub.php, (c) admin.php, (d)...

1 affected packages

b2evolution

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
b2evolution
Show less packages

CVE-2007-1002

Unknown priority
Fixed

Format string vulnerability in the write_html function in calendar/gui/e-cal-component-memo-preview.c in Evolution Shared Memo 2.8.2.1, and possibly earlier versions, allows user-assisted remote attackers to execute arbitrary code...

1 affected packages

evolution

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
evolution
Show less packages

CVE-2007-1266

Unknown priority
Ignored

Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between signed and unsigned portions of OpenPGP messages with...

1 affected packages

evolution

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
evolution
Show less packages

CVE-2007-0175

Unknown priority

Some fixes available 1 of 4

Cross-site scripting (XSS) vulnerability in htsrv/login.php in b2evolution 1.8.6 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes in the redirect_to parameter.

1 affected packages

b2evolution

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
b2evolution
Show less packages

CVE-2006-2789

Unknown priority
Not affected

Evolution 2.2.x and 2.3.x in GNOME 2.7 and 2.8, when "load images if sender in addressbook" is enabled, allows remote attackers to cause a denial of service (persistent crash) via a crafted "From" header that triggers an assert...

1 affected packages

evolution

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
evolution
Show less packages