7.5

CVE-2005-2549

Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers.

Data is provided by the National Vulnerability Database (NVD)
GnomeEvolution Version1.5
GnomeEvolution Version2.0
GnomeEvolution Version2.1
GnomeEvolution Version2.2
GnomeEvolution Version2.3.1
GnomeEvolution Version2.3.2
GnomeEvolution Version2.3.3
GnomeEvolution Version2.3.4
GnomeEvolution Version2.3.5
GnomeEvolution Version2.3.6.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.93% 0.852
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P