Evolution 中发现了一个缺陷。远程攻击者可以通过发送一封经过精心构造的 HTML 电子邮件来利用此漏洞,该邮件中包含一个伪造的 vCard 控件。当受害者点击该控件时,Evolution 中受信任的 JavaScript 处理程序错误地将攻击者控制的 JavaScript URL 赋给 iframe 的 source 属性。这一操作导致在查看邮件的上下文中执行任意 JavaScript,从而有效规避了旨在防止电子邮件内容中脚本执行的安全机制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84042 | 7.8 HIGH | Crun: crun: rootful krun with passt executes container payload as host root |
| CVE-2026-88924 | 7.0 HIGH | Gvfs: gvfs-admin socket ownership race permits local root |
| CVE-2026-84828 | 6.5 MEDIUM | Pcs: pcs: non-root haclient users can read arbitrary files via pcs host auth --token |
| CVE-2026-88770 | 6.5 MEDIUM | Keycloak-services: keycloak-services: device authorization grant issues tokens to brute-fo |
| CVE-2026-88763 | 5.9 MEDIUM | Skupper-router: skupper-router: unbounded recursion in amqp field parser leads to denial o |
| CVE-2026-88265 | 5.6 MEDIUM | Crun: crun: /dev/null symlink follow during stdio reopen allows host bind-mount write and |
| CVE-2026-88264 | 5.6 MEDIUM | Crun: crun: /dev/console symlink follow allows root-owned file creation outside the rootfs |
No comments yet