Evolution Data Server
Vendor:
First CVE: Mar 14, 2009 · Active for 17 years
4
Total CVEs
More Total CVEs than 72% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Evolution Data Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 14, 2009
17 years ago
Most Recent CVE
Jul 29, 2020
2,186 days ago
CVE Severity & Scoring
Evolution Data Server4 CVEs
75%
25%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network3 (75.0%)
Unknown1 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (25.0%)
High2 (50.0%)
Unknown1 (25.0%)
User Interaction
None3 (75.0%)
Unknown1 (25.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (75.0%)
Unknown1 (25.0%)
Top CVEs
Signals from CVEs in this product scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-4166HIGH The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG ke | Feb 6, 2020 | 7.5 | 22 | NO | NO |
CVE-2009-0582MEDIUM The ntlm_challenge function in the NTLM SASL authentication mechanism in camel/camel-sasl-ntlm.c in Camel in Evolution Data Server (aka evolution-data-server) 2.24.5 and earlier, a | Mar 14, 2009 | 5.8 | 18 | NO | NO |
CVE-2020-16117MEDIUM In GNOME evolution-data-server before 3.35.91, a malicious server can crash the mail client with a NULL pointer dereference by sending an invalid (e.g., minimal) CAPABILITY line on | Jul 29, 2020 | 5.9 | 17 | NO | NO |
CVE-2020-14928MEDIUM evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and eval | Jul 17, 2020 | 5.9 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (4 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (4 CVEs).
Media Mentions
Signals from CVEs in this product scope (4 CVEs).
Top CNAs Publishing CVEs For Evolution Data Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.25.92 | 1 | 5.8 | 2.3% | 0 | 0 |