Evolution

Vendor:

First CVE: Jan 24, 2005 · Active for 21 years

22
Total CVEs
More Total CVEs than 94% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Evolution over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 24, 2005
21 years ago
Most Recent CVE
May 26, 2021
1,885 days ago

CVE Severity & Scoring

Evolution22 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local2 (9.1%)
Network7 (31.8%)
Unknown13 (59.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (36.4%)
High1 (4.5%)
Unknown13 (59.1%)
User Interaction
None6 (27.3%)
Unknown13 (59.1%)
Required3 (13.6%)
Privileges Required
Low1 (4.5%)
High0 (0.0%)
None8 (36.4%)
Unknown13 (59.1%)

Top CVEs

Signals from CVEs in this product scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, a
Aug 3, 20099.331NONO
Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which l
Jan 24, 20059.830NONO
addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger a Buffer Overflow via a long query that
Jun 15, 20189.828NONO
Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attackers to execute arbitrary code via a long DESCRIPTION property in an iCalendar attachment, which is
Jun 4, 20089.327NONO
The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached
Feb 2, 20065.027NOYES
camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wish
Jul 20, 20189.826NONO
Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause th
May 26, 20217.824NONO
Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between signed and unsigned po
Mar 6, 20075.024NOYES
Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled, allows remote attackers to execute arbitrary code via a long timezone string in an iCalendar attach
Jun 4, 20087.623NONO
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG ke
Feb 6, 20207.522NONO

Exploit Exposure

Signals from CVEs in this product scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
9.1% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (22 CVEs).

Media Mentions

Signals from CVEs in this product scope (22 CVEs).

Top CNAs Publishing CVEs For Evolution

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.8.114.32.7%00
2.623.21.6%00
2.4.2.124.72.3%00
2.423.21.6%00
2.3.734.05.3%01
2.3.6.155.44.9%01
2.3.634.05.3%01
2.3.555.44.9%01
2.3.455.44.9%01
2.3.355.44.9%01
2.32.314.32.7%00
2.3.255.44.9%01
2.3.155.44.9%01
2.30.314.32.7%00
2.28.3.114.32.7%00
2.26.314.32.7%00
2.26.114.32.7%00
2.24.514.32.7%00
2.2423.21.6%00
2.22.314.32.7%00