VDB
CVE-2009-0587
CVE-2009-0587
PUBLISHED
CVSS 7.5 HIGH
Multiple integer overflows in Evolution Data Server (aka evolution-data-server) before 2.24.5 allow context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation in (1) addressbook/libebook/e-vcard.c in evc or (2) camel/camel-mime-utils.c in libcamel.
EPSS 1.89% · 83.5th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
1.89%
83.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| go-evolution | evolution-data-server | 0 |
| n/a | n/a | n/a |
Timeline
- Mar 14, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 3, 2023 EPSS Score
- Feb 9, 2023 EPSS Score
- Feb 13, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- 35357 third-party-advisory
- 52703 vdb
- USN-733-1 vendor-advisory
- oval:org.mitre.oval:def:11385 vdb
- 34339 third-party-advisory
- RHSA-2009:0358 vendor-advisory
- 34348 third-party-advisory
- [oss-security] 20090312 [oCERT-2008-015] glib and glib-predecessor heap overflows mailing-list
- 34100 vdb
- 34351 third-party-advisory
- RHSA-2009:0355 vendor-advisory
- 20090312 [oCERT-2008-015] glib and glib-predecessor heap overflows mailing-list
- DSA-1813 vendor-advisory
- SUSE-SR:2010:012 vendor-advisory
- 52702 vdb
- RHSA-2009:0354 vendor-advisory
- 34338 third-party-advisory
- MDVSA-2009:078 vendor-advisory
- http://ocert.org/patches/2008-015/camel-CVE-2009-0587.diff url
- http://ocert.org/patches/2008-015/evc-CVE-2009-0587.diff url
…and 7 more