Evolution
Vendor:
First CVE: Jan 24, 2005 · Active for 21 years
22
Total CVEs
More Total CVEs than 94% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Evolution over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 24, 2005
21 years ago
Most Recent CVE
May 26, 2021
1,885 days ago
CVE Severity & Scoring
Evolution22 CVEs
14%
41%
32%
14%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (9.1%)
Network7 (31.8%)
Unknown13 (59.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (36.4%)
High1 (4.5%)
Unknown13 (59.1%)
User Interaction
None6 (27.3%)
Unknown13 (59.1%)
Required3 (13.6%)
Privileges Required
Low1 (4.5%)
High0 (0.0%)
None8 (36.4%)
Unknown13 (59.1%)
Top CVEs
Signals from CVEs in this product scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-2404HIGH Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, a | Aug 3, 2009 | 9.3 | 31 | NO | NO |
CVE-2005-0102CRITICAL Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which l | Jan 24, 2005 | 9.8 | 30 | NO | NO |
CVE-2018-12422CRITICAL addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger a Buffer Overflow via a long query that | Jun 15, 2018 | 9.8 | 28 | NO | NO |
CVE-2008-1109HIGH Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attackers to execute arbitrary code via a long DESCRIPTION property in an iCalendar attachment, which is | Jun 4, 2008 | 9.3 | 27 | NO | NO |
CVE-2006-0528MEDIUM The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached | Feb 2, 2006 | 5.0 | 27 | NO | YES |
CVE-2016-10727CRITICAL camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wish | Jul 20, 2018 | 9.8 | 26 | NO | NO |
CVE-2009-3721HIGH Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause th | May 26, 2021 | 7.8 | 24 | NO | NO |
CVE-2007-1266MEDIUM Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between signed and unsigned po | Mar 6, 2007 | 5.0 | 24 | NO | YES |
CVE-2008-1108HIGH Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled, allows remote attackers to execute arbitrary code via a long timezone string in an iCalendar attach | Jun 4, 2008 | 7.6 | 23 | NO | NO |
CVE-2013-4166HIGH The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG ke | Feb 6, 2020 | 7.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (22 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
9.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (22 CVEs).
Media Mentions
Signals from CVEs in this product scope (22 CVEs).
Top CNAs Publishing CVEs For Evolution
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.8.1 | 1 | 4.3 | 2.7% | 0 | 0 |
| 2.6 | 2 | 3.2 | 1.6% | 0 | 0 |
| 2.4.2.1 | 2 | 4.7 | 2.3% | 0 | 0 |
| 2.4 | 2 | 3.2 | 1.6% | 0 | 0 |
| 2.3.7 | 3 | 4.0 | 5.3% | 0 | 1 |
| 2.3.6.1 | 5 | 5.4 | 4.9% | 0 | 1 |
| 2.3.6 | 3 | 4.0 | 5.3% | 0 | 1 |
| 2.3.5 | 5 | 5.4 | 4.9% | 0 | 1 |
| 2.3.4 | 5 | 5.4 | 4.9% | 0 | 1 |
| 2.3.3 | 5 | 5.4 | 4.9% | 0 | 1 |
| 2.32.3 | 1 | 4.3 | 2.7% | 0 | 0 |
| 2.3.2 | 5 | 5.4 | 4.9% | 0 | 1 |
| 2.3.1 | 5 | 5.4 | 4.9% | 0 | 1 |
| 2.30.3 | 1 | 4.3 | 2.7% | 0 | 0 |
| 2.28.3.1 | 1 | 4.3 | 2.7% | 0 | 0 |
| 2.26.3 | 1 | 4.3 | 2.7% | 0 | 0 |
| 2.26.1 | 1 | 4.3 | 2.7% | 0 | 0 |
| 2.24.5 | 1 | 4.3 | 2.7% | 0 | 0 |
| 2.24 | 2 | 3.2 | 1.6% | 0 | 0 |
| 2.22.3 | 1 | 4.3 | 2.7% | 0 | 0 |