← All CVEs

CVE-2006-0528

medium · 5

The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains "Content-Disposition: inline" in the header, and a very long line in the body, which causes the client to repeatedly crash until the e-mail message is manually removed, possibly due to a buffer overflow, as demonstrated using an XML attachment.

5
CVSS
11.0%
EPSS (exploit prob.)
96th
EPSS percentile
2006-02-02
Published

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

VendorProductAffected versions
gnomeevolution2.3.1
gnomeevolution2.3.2
gnomeevolution2.3.3
gnomeevolution2.3.4
gnomeevolution2.3.5
gnomeevolution2.3.6
gnomeevolution2.3.6.1
gnomeevolution2.3.7

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-0528