📦

evolution

Vendor: gnome

Actively Exploited 0 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 3 Remote Access
Total CVEs 38 Total Indexed
Avg. EPSS 3.54% Exploit Prob.
Latest CVE CVE-2009-3721 May 26

Security Vulnerability Index

Page 3 / 4
7.5 CVSS

Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entries such as task lists, which are not properly handled when the user selects the Calendars tab.

EPSS: 4.43%
9.8 CVSS

Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow.

EPSS: 3.18%