VDB
CVE-2005-2550
CVE-2005-2550
PUBLISHED
CVSS 7.5 HIGH
Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entries such as task lists, which are not properly handled when the user selects the Calendars tab.
EPSS 4.43% · 90.6th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
4.43%
90.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| gnome | evolution | 2.3.4, 1.4, 1.5 |
| n/a | n/a | n/a |
Timeline
- Aug 12, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 3, 2023 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
References
- DSA-1016 vendor-advisory
- 20050810 Evolution multiple remote format string bugs mailing-list
- USN-166-1 vendor-advisory
- RHSA-2005:267 vendor-advisory
- http://www.sitic.se/eng/advisories_and_recommendations/sa05-001.html url
- 20050810 Evolution multiple remote format string bugs mailing-list
- http://www.securityfocus.com/bid/14532 technical
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10880 technical
- http://secunia.com/advisories/16394 technical
- http://secunia.com/advisories/19380 technical
- http://www.novell.com/linux/security/advisories/2005_54_evolution.html technical
- http://www.redhat.com/archives/fedora-announce-list/2005-August/msg00031.html technical
- https://nvd.nist.gov/vuln/detail/CVE-2005-2550 advisory
- https://usn.ubuntu.com/166-1 url
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:141 url