VYPR

evolution-data-server

by Evolution

CVEs (2)

  • CVE-2009-0587Mar 14, 2009
    risk 0.00cvss epss 0.03

    Multiple integer overflows in Evolution Data Server (aka evolution-data-server) before 2.24.5 allow context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation in (1) addressbook/libebook/e-vcard.c in evc or (2)…

  • CVE-2009-0582Mar 14, 2009
    risk 0.00cvss epss 0.02

    The ntlm_challenge function in the NTLM SASL authentication mechanism in camel/camel-sasl-ntlm.c in Camel in Evolution Data Server (aka evolution-data-server) 2.24.5 and earlier, and 2.25.92 and earlier 2.25.x versions, does not validate whether a certain length value is…