Tnef Project
Tnef Project Tnef: vulnerabilidades y CVE
Tnef Project Tnef tiene 9 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses3
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-103680 | Media (6.5) | 0.29% | — | 1 oct 2026 | A flaw was found in tnef. A heap-based buffer overflow can occur in the find_free_number() function when generating numbered backup suffixes for duplicate filenames. When numbered backups are enabled and file… |
| CVE-2026-103679 | Media (6.5) | 0.30% | — | 1 oct 2026 | A flaw was found in tnef. A remote attacker could exploit this vulnerability by providing a specially crafted Transport Neutral Encapsulation Format (TNEF) file containing multiple message bodies. During extraction,… |
| CVE-2026-103678 | Alta (8.1) | 0.21% | — | 1 oct 2026 | A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input… |
| CVE-2019-18849 | Media (5.5) | 1.2% | — | 11 nov 2019 | In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read… |
| CVE-2017-8911 | Crítica (9.8) | 1.9% | — | 12 may 2017 | An integer underflow has been identified in the unicode_to_utf8() function in tnef 1.4.14. This might lead to invalid write operations, controlled by an attacker. |
| CVE-2017-6310 | Alta (7.8) | 1.4% | — | 24 feb 2017 | An issue was discovered in tnef before 1.4.13. Four type confusions have been identified in the file_add_mapi_attrs() function. These might lead to invalid read and write operations, controlled by an attacker. |
| CVE-2017-6309 | Alta (7.8) | 1.4% | — | 24 feb 2017 | An issue was discovered in tnef before 1.4.13. Two type confusions have been identified in the parse_file() function. These might lead to invalid read and write operations, controlled by an attacker. |
| CVE-2017-6308 | Alta (7.8) | 1.5% | — | 24 feb 2017 | An issue was discovered in tnef before 1.4.13. Several Integer Overflows, which can lead to Heap Overflows, have been identified in the functions that wrap memory allocation. |
| CVE-2017-6307 | Alta (7.8) | 1.4% | — | 24 feb 2017 | An issue was discovered in tnef before 1.4.13. Two OOB Writes have been identified in src/mapi_attr.c:mapi_attr_read(). These might lead to invalid read and write operations, controlled by an attacker. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.