Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2571▼ 304 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

36 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
En análisisBaja (3.1)0.29%—TnefAI1/10/20261/10/2026
A flaw was found in tnef. A heap-based buffer overflow can occur in the find_free_number() function when generating numbered backup suffixes for duplicate filenames. When numbered backups are enabled and file overwriting is disabled, an attacker can supply a specially crafted Transport Neutral Encapsulation Format…
En análisisMedia (6.5)0.30%—TnefAI1/10/20261/10/2026
A flaw was found in tnef. A remote attacker could exploit this vulnerability by providing a specially crafted Transport Neutral Encapsulation Format (TNEF) file containing multiple message bodies. During extraction, improper memory management triggers a use-after-free and double-free condition, causing the application…
En análisisMedia (5.4)0.21%—TnefAI1/10/20261/10/2026
A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in get_rtf_data_from_buf(), reading beyond the allocated memory…
ModificadaAlta (7.8)1.6%—Gnome EvolutionYtnef Project Ytnef26/5/202116/6/2026
Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesystem, crash, or potentially execute arbitrary code when decoding…
ModificadaAlta (7.8)1.9%—Ytnef Project YtnefRedhat Enterprise LinuxFedoraproject Fedora4/3/202117/6/2026
In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a heap buffer overflow which can be triggered via a crafted file.
ModificadaAlta (7.8)1.8%—Ytnef Project YtnefRedhat Enterprise LinuxFedoraproject Fedora4/3/202117/6/2026
In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a double free which can be triggered via a crafted file.
ModificadaMedia (5.5)1.2%—Tnef Project TnefFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux11/11/201917/6/2026
In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup.
ModificadaCrítica (9.8)2.5%—Ytnef Project Ytnef29/10/201916/6/2026
ytnef has directory traversal
ModificadaMedia (5.5)1.0%—Ytnef Project Ytnef2/8/201717/6/2026
In ytnef 1.9.2, an allocation failure was found in the function TNEFFillMapi in ytnef.c, which allows attackers to cause a denial of service via a crafted file.
ModificadaMedia (5.5)0.97%—Ytnef Project Ytnef2/8/201717/6/2026
In ytnef 1.9.2, an invalid memory read vulnerability was found in the function SwapDWord in ytnef.c, which allows attackers to cause a denial of service via a crafted file.
ModificadaMedia (5.5)1.1%—Ytnef Project Ytnef2/8/201717/6/2026
In ytnef 1.9.2, a heap-based buffer overflow vulnerability was found in the function TNEFFillMapi in ytnef.c, which allows attackers to cause a denial of service via a crafted file.
ModificadaMedia (5.5)0.94%—Ytnef Project Ytnef7/6/201717/6/2026
In ytnef 1.9.2, the DecompressRTF function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
ModificadaMedia (5.5)1.2%—Ytnef Project YtnefCanonical Ubuntu Linux7/6/201717/6/2026
In ytnef 1.9.2, the TNEFFillMapi function in lib/ytnef.c allows remote attackers to cause a denial of service (memory consumption) via a crafted file.
ModificadaMedia (5.5)0.94%—Ytnef Project Ytnef7/6/201717/6/2026
In ytnef 1.9.2, the SwapDWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
ModificadaMedia (5.5)1.2%—Ytnef Project YtnefCanonical Ubuntu Linux7/6/201717/6/2026
In ytnef 1.9.2, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
ModificadaMedia (5.5)0.94%—Ytnef Project Ytnef7/6/201717/6/2026
In ytnef 1.9.2, the MAPIPrint function in lib/ytnef.c allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.
ModificadaAlta (8.8)2.4%—Ytnef Project Ytnef22/5/201717/6/2026
The TNEFFillMapi function in lib/ytnef.c in libytnef in ytnef through 1.9.2 does not ensure a nonzero count value before a certain memory allocation, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted…
ModificadaCrítica (9.8)1.5%—Ytnef Project YtnefCanonical Ubuntu Linux18/5/201717/6/2026
In libytnef in ytnef through 1.9.2, there is a heap-based buffer over-read due to incorrect boundary checking in the SIZECHECK macro in lib/ytnef.c.
ModificadaCrítica (9.8)1.9%—Tnef Project Tnef12/5/201717/6/2026
An integer underflow has been identified in the unicode_to_utf8() function in tnef 1.4.14. This might lead to invalid write operations, controlled by an attacker.
ModificadaAlta (7.5)1.4%—Ytnef Project YtnefDebian Linux10/3/201717/6/2026
An issue was discovered in ytnef before 1.9.2. There is a potential heap-based buffer over-read on incoming Compressed RTF Streams, related to DecompressRTF() in libytnef.
ModificadaAlta (7.5)1.9%—Ytnef Project YtnefDebian Linux10/3/201717/6/2026
An issue was discovered in ytnef before 1.9.2. There is a potential out-of-bounds access with fields of Size 0 in TNEFParse() in libytnef.
ModificadaAlta (7.5)1.7%—Ytnef Project YtnefDebian Linux10/3/201717/6/2026
An issue was discovered in ytnef before 1.9.2. An invalid memory access (heap-based buffer over-read) can occur during handling of LONG data types, related to MAPIPrint() in libytnef.
ModificadaAlta (7.8)1.4%—Tnef Project TnefDebian Linux24/2/201717/6/2026
An issue was discovered in tnef before 1.4.13. Four type confusions have been identified in the file_add_mapi_attrs() function. These might lead to invalid read and write operations, controlled by an attacker.
ModificadaAlta (7.8)1.4%—Tnef Project TnefDebian Linux24/2/201717/6/2026
An issue was discovered in tnef before 1.4.13. Two type confusions have been identified in the parse_file() function. These might lead to invalid read and write operations, controlled by an attacker.
ModificadaAlta (7.8)1.5%—Tnef Project TnefDebian Linux24/2/201717/6/2026
An issue was discovered in tnef before 1.4.13. Several Integer Overflows, which can lead to Heap Overflows, have been identified in the functions that wrap memory allocation.