Show filters
200 Total Results
Displaying 161-170 of 200
Sort by:
Attacker Value
Unknown

CVE-2009-1457

Disclosure Date: April 28, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in player.php in Nuke Evolution Xtreme 2.x allows remote attackers to inject arbitrary web script or HTML via the defaultVisualExt parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2009-0582

Disclosure Date: March 14, 2009 (last updated October 04, 2023)
The ntlm_challenge function in the NTLM SASL authentication mechanism in camel/camel-sasl-ntlm.c in Camel in Evolution Data Server (aka evolution-data-server) 2.24.5 and earlier, and 2.25.92 and earlier 2.25.x versions, does not validate whether a certain length value is consistent with the amount of data in a challenge packet, which allows remote mail servers to read information from the process memory of a client, or cause a denial of service (client crash), via an NTLM authentication type 2 packet with a length value that exceeds the amount of packet data.
0
Attacker Value
Unknown

CVE-2009-0587

Disclosure Date: March 14, 2009 (last updated October 04, 2023)
Multiple integer overflows in Evolution Data Server (aka evolution-data-server) before 2.24.5 allow context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation in (1) addressbook/libebook/e-vcard.c in evc or (2) camel/camel-mime-utils.c in libcamel.
0
Attacker Value
Unknown

CVE-2009-0547

Disclosure Date: February 12, 2009 (last updated October 04, 2023)
Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.
0
Attacker Value
Unknown

CVE-2008-1109

Disclosure Date: June 04, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attackers to execute arbitrary code via a long DESCRIPTION property in an iCalendar attachment, which is not properly handled during a reply in the calendar view (aka the Calendars window).
0
Attacker Value
Unknown

CVE-2008-1108

Disclosure Date: June 04, 2008 (last updated October 04, 2023)
Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled, allows remote attackers to execute arbitrary code via a long timezone string in an iCalendar attachment.
0
Attacker Value
Unknown

CVE-2008-0072

Disclosure Date: March 06, 2008 (last updated October 04, 2023)
Format string vulnerability in the emf_multipart_encrypted function in mail/em-format.c in Evolution 2.12.3 and earlier allows remote attackers to execute arbitrary code via a crafted encrypted message, as demonstrated using the Version field.
0
Attacker Value
Unknown

CVE-2007-6221

Disclosure Date: December 04, 2007 (last updated October 04, 2023)
TuMusika Evolution 1.7R5 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2007-6188

Disclosure Date: November 30, 2007 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in TuMusika Evolution 1.7R5 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter to (1) languages_n.php, (2) languages_f.php, or (3) languages.php in inc/; and (4) allow remote attackers to read arbitrary local files via a .. (dot dot) in the uri parameter to frames/nogui/sc_download.php.
0
Attacker Value
Unknown

CVE-2007-4832

Disclosure Date: September 12, 2007 (last updated October 04, 2023)
Format string vulnerability in CellFactor Revolution 1.03 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a malformed nickname.
0