Search CVE reports


Toggle filters

11 – 20 of 37 results


CVE-2016-10727

Medium priority
Fixed

camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not...

1 affected package

evolution-data-server

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
evolution-data-server Not affected
Show less packages

CVE-2018-12422

Medium priority
Ignored

addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger a Buffer Overflow via a long query that is processed by the strcat function. NOTE: the...

2 affected packages

evolution, evolution-data-server

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
evolution Ignored
evolution-data-server Ignored
Show less packages

CVE-2017-17689

Medium priority

Some fixes available 22 of 34

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

5 affected packages

evolution, kdepim, kf5-messagelib, kmail, thunderbird

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
evolution Not affected Not affected Not affected Not affected
kdepim Not in release Not in release
kf5-messagelib Not affected Not affected Not affected Fixed
kmail Not affected Not affected Not affected Fixed
thunderbird Fixed Fixed Fixed Fixed
Show less packages

CVE-2014-1639

Medium priority
Ignored

syncevo/installcheck-local.sh in syncevolution before 1.3.99.7 uses mktemp to create a safe temporary file but appends a suffix to the original filename and writes to this new filename, which allows local users to overwrite...

1 affected package

syncevolution

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
syncevolution Not affected
Show less packages

CVE-2013-4166

Medium priority

Some fixes available 3 of 4

The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause...

1 affected package

evolution-data-server

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
evolution-data-server
Show less packages

CVE-2011-3201

Low priority
Not affected

GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter to a mailto: URL, which attaches the file to the email.

1 affected package

evolution

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
evolution
Show less packages

CVE-2012-1177

Medium priority

Some fixes available 4 of 6

libgdata before 0.10.2 and 0.11.x before 0.11.1 does not validate SSL certificates, which allows remote attackers to obtain user names and passwords via a man-in-the-middle (MITM) attack with a spoofed certificate.

2 affected packages

evolution-data-server, libgdata

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
evolution-data-server
libgdata
Show less packages

CVE-2011-3709

Low priority
Ignored

b2evolution 3.3.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by locales/ru_RU/ru-RU.locale.php and certain...

1 affected package

b2evolution

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
b2evolution
Show less packages

CVE-2009-1631

Low priority
Ignored

The Mailer component in Evolution 2.26.1 and earlier uses world-readable permissions for the .evolution directory, and certain directories and files under .evolution/ related to local mail, which allows local users to...

1 affected package

evolution

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
evolution
Show less packages

CVE-2009-0587

Medium priority
Fixed

Multiple integer overflows in Evolution Data Server (aka evolution-data-server) before 2.24.5 allow context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation in (1)...

1 affected package

evolution-data-server

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
evolution-data-server
Show less packages