Gnome

Evolution

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.78%
  • Veröffentlicht 26.05.2021 22:15:07
  • Zuletzt bearbeitet 21.11.2024 01:08:03

Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesyste...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 01.02.2021 05:15:11
  • Zuletzt bearbeitet 21.11.2024 06:21:21

GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information from the GnuPG API. NOTE: third parties dispute the significance of this ...

  • EPSS 0.54%
  • Veröffentlicht 17.04.2020 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:58:48

An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make Evolution attach local files or directories to a composed email mess...

  • EPSS 1.01%
  • Veröffentlicht 06.02.2020 15:15:10
  • Zuletzt bearbeitet 21.11.2024 01:55:00

The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encry...

Exploit
  • EPSS 1.2%
  • Veröffentlicht 11.02.2019 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:51:07

GNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that contains a valid signature from the entity to be impersonated as an attachment.

Exploit
  • EPSS 1.08%
  • Veröffentlicht 20.07.2018 04:29:00
  • Zuletzt bearbeitet 21.11.2024 02:44:36

camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes i...

  • EPSS 0.54%
  • Veröffentlicht 15.06.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:45:11

addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger a Buffer Overflow via a long query that is processed by the strcat function. NOTE: the software maintainer dis...

Exploit
  • EPSS 0.87%
  • Veröffentlicht 16.05.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:18:27

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

  • EPSS 0.81%
  • Veröffentlicht 08.03.2013 21:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter to a mailto: URL, which attaches the file to the email.

Exploit
  • EPSS 0.11%
  • Veröffentlicht 14.05.2009 17:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The Mailer component in Evolution 2.26.1 and earlier uses world-readable permissions for the .evolution directory, and certain directories and files under .evolution/ related to local mail, which allows local users to obtain sensitive information by ...