Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown

CVE-2011-3201

Disclosure Date: March 08, 2013 (last updated October 05, 2023)
GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter to a mailto: URL, which attaches the file to the email.
0
Attacker Value
Unknown

CVE-2009-5103

Disclosure Date: October 21, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in ATCOM Netvolution 1.0 ASP allows remote attackers to inject arbitrary web script or HTML via the email variable.
0
Attacker Value
Unknown

CVE-2009-5102

Disclosure Date: October 21, 2011 (last updated October 04, 2023)
SQL injection vulnerability in default.asp in ATCOM Netvolution 1.0 ASP allows remote attackers to execute arbitrary SQL commands via the bpe_nid parameter.
0
Attacker Value
Unknown

CVE-2010-3929

Disclosure Date: February 02, 2011 (last updated October 04, 2023)
SQL injection vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors related to AjaxSearch.
0
Attacker Value
Unknown

CVE-2011-0741

Disclosure Date: February 02, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ModX Evolution before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) installer or (2) image editor.
0
Attacker Value
Unknown

CVE-2010-3930

Disclosure Date: February 02, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to read arbitrary files via unspecified vectors related to AjaxSearch, a different vulnerability than CVE-2010-1427.
0
Attacker Value
Unknown

CVE-2009-1631

Disclosure Date: May 14, 2009 (last updated October 04, 2023)
The Mailer component in Evolution 2.26.1 and earlier uses world-readable permissions for the .evolution directory, and certain directories and files under .evolution/ related to local mail, which allows local users to obtain sensitive information by reading these files.
0
Attacker Value
Unknown

CVE-2002-1471

Disclosure Date: April 22, 2003 (last updated February 22, 2025)
The camel component for Ximian Evolution 1.0.x and earlier does not verify certificates when it establishes a new SSL connection after previously verifying a certificate, which could allow remote attackers to monitor or modify sessions via a man-in-the-middle attack.
0
Attacker Value
Unknown

CVE-2003-0129

Disclosure Date: March 24, 2003 (last updated February 22, 2025)
Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that is uuencoded multiple times.
0
Attacker Value
Unknown

CVE-2003-0130

Disclosure Date: March 24, 2003 (last updated February 22, 2025)
The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers to inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded image.
0