CVE-2011-3201

UnknownEPSS 2.67%

Last modified

CVE-2011-3201 is a vulnerability of currently unknown severity. GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter to a mailto: URL, which attaches the file to the email.. EPSS estimates a 2.67% chance of exploitation in the next 30 days.

Description

GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter to a mailto: URL, which attaches the file to the email.

Metrics

EPSS Probability
2.67%

83.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
OracleSolaris11.2
GnomeEvolution<= 3.0.3
GnomeEvolution1.0.8
GnomeEvolution1.2
GnomeEvolution1.2.1
GnomeEvolution1.2.2
GnomeEvolution1.2.3
GnomeEvolution1.2.4
GnomeEvolution1.4
GnomeEvolution1.4.3
GnomeEvolution1.4.4
GnomeEvolution1.4.5
GnomeEvolution1.4.6
GnomeEvolution1.5
GnomeEvolution1.11
GnomeEvolution2.0
GnomeEvolution2.0.0
GnomeEvolution2.0.1
GnomeEvolution2.0.2
GnomeEvolution2.1
GnomeEvolution2.2
GnomeEvolution2.2.1
GnomeEvolution2.3.1
GnomeEvolution2.3.2
GnomeEvolution2.3.3
GnomeEvolution2.3.4
GnomeEvolution2.3.5
GnomeEvolution2.3.6
GnomeEvolution2.3.6.1
GnomeEvolution2.3.7
GnomeEvolution2.4
GnomeEvolution2.4.2.1
GnomeEvolution2.6
GnomeEvolution2.8.1
GnomeEvolution2.10.3
GnomeEvolution2.12
GnomeEvolution2.12.3
GnomeEvolution2.22.1
GnomeEvolution2.22.3
GnomeEvolution2.24
GnomeEvolution2.24.5
GnomeEvolution2.26.1
GnomeEvolution2.26.3
GnomeEvolution2.28.3.1
GnomeEvolution2.30.3
GnomeEvolution2.32.3
RedhatEnterprise Linux Desktop6.0
RedhatEnterprise Linux Server6.0
RedhatEnterprise Linux Workstation6.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2011-3201?
GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter to a mailto: URL, which attaches the file to the email.
How severe is CVE-2011-3201?
Severity scoring for CVE-2011-3201 is pending analysis. The EPSS model estimates a 2.67% probability of exploitation in the next 30 days.
How do I fix CVE-2011-3201?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2011-3201?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST