Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2571▼ 304 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Baja (3.1) | 0.29% | — | TnefAI | 1/10/2026 | 1/10/2026 | A flaw was found in tnef. A heap-based buffer overflow can occur in the find_free_number() function when generating numbered backup suffixes for duplicate filenames. When numbered backups are enabled and file overwriting is disabled, an attacker can supply a specially crafted Transport Neutral Encapsulation Format… | |
| En análisis | Media (6.5) | 0.30% | — | TnefAI | 1/10/2026 | 1/10/2026 | A flaw was found in tnef. A remote attacker could exploit this vulnerability by providing a specially crafted Transport Neutral Encapsulation Format (TNEF) file containing multiple message bodies. During extraction, improper memory management triggers a use-after-free and double-free condition, causing the application… | |
| En análisis | Media (5.4) | 0.21% | — | TnefAI | 1/10/2026 | 1/10/2026 | A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in get_rtf_data_from_buf(), reading beyond the allocated memory… | |
| Modificada | Alta (7.8) | 1.6% | — | Gnome EvolutionYtnef Project Ytnef | 26/5/2021 | 16/6/2026 | Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesystem, crash, or potentially execute arbitrary code when decoding… | |
| Modificada | Alta (7.8) | 1.9% | — | Ytnef Project YtnefRedhat Enterprise LinuxFedoraproject Fedora | 4/3/2021 | 17/6/2026 | In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a heap buffer overflow which can be triggered via a crafted file. | |
| Modificada | Alta (7.8) | 1.8% | — | Ytnef Project YtnefRedhat Enterprise LinuxFedoraproject Fedora | 4/3/2021 | 17/6/2026 | In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a double free which can be triggered via a crafted file. | |
| Modificada | Media (5.5) | 1.2% | — | Tnef Project TnefFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux | 11/11/2019 | 17/6/2026 | In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup. | |
| Modificada | Crítica (9.8) | 2.5% | — | Ytnef Project Ytnef | 29/10/2019 | 16/6/2026 | ytnef has directory traversal | |
| Modificada | Media (5.5) | 1.0% | — | Ytnef Project Ytnef | 2/8/2017 | 17/6/2026 | In ytnef 1.9.2, an allocation failure was found in the function TNEFFillMapi in ytnef.c, which allows attackers to cause a denial of service via a crafted file. | |
| Modificada | Media (5.5) | 0.97% | — | Ytnef Project Ytnef | 2/8/2017 | 17/6/2026 | In ytnef 1.9.2, an invalid memory read vulnerability was found in the function SwapDWord in ytnef.c, which allows attackers to cause a denial of service via a crafted file. | |
| Modificada | Media (5.5) | 1.1% | — | Ytnef Project Ytnef | 2/8/2017 | 17/6/2026 | In ytnef 1.9.2, a heap-based buffer overflow vulnerability was found in the function TNEFFillMapi in ytnef.c, which allows attackers to cause a denial of service via a crafted file. | |
| Modificada | Media (5.5) | 0.94% | — | Ytnef Project Ytnef | 7/6/2017 | 17/6/2026 | In ytnef 1.9.2, the DecompressRTF function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file. | |
| Modificada | Media (5.5) | 1.2% | — | Ytnef Project YtnefCanonical Ubuntu Linux | 7/6/2017 | 17/6/2026 | In ytnef 1.9.2, the TNEFFillMapi function in lib/ytnef.c allows remote attackers to cause a denial of service (memory consumption) via a crafted file. | |
| Modificada | Media (5.5) | 0.94% | — | Ytnef Project Ytnef | 7/6/2017 | 17/6/2026 | In ytnef 1.9.2, the SwapDWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file. | |
| Modificada | Media (5.5) | 1.2% | — | Ytnef Project YtnefCanonical Ubuntu Linux | 7/6/2017 | 17/6/2026 | In ytnef 1.9.2, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file. | |
| Modificada | Media (5.5) | 0.94% | — | Ytnef Project Ytnef | 7/6/2017 | 17/6/2026 | In ytnef 1.9.2, the MAPIPrint function in lib/ytnef.c allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file. | |
| Modificada | Alta (8.8) | 2.4% | — | Ytnef Project Ytnef | 22/5/2017 | 17/6/2026 | The TNEFFillMapi function in lib/ytnef.c in libytnef in ytnef through 1.9.2 does not ensure a nonzero count value before a certain memory allocation, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted… | |
| Modificada | Crítica (9.8) | 1.5% | — | Ytnef Project YtnefCanonical Ubuntu Linux | 18/5/2017 | 17/6/2026 | In libytnef in ytnef through 1.9.2, there is a heap-based buffer over-read due to incorrect boundary checking in the SIZECHECK macro in lib/ytnef.c. | |
| Modificada | Crítica (9.8) | 1.9% | — | Tnef Project Tnef | 12/5/2017 | 17/6/2026 | An integer underflow has been identified in the unicode_to_utf8() function in tnef 1.4.14. This might lead to invalid write operations, controlled by an attacker. | |
| Modificada | Alta (7.5) | 1.4% | — | Ytnef Project YtnefDebian Linux | 10/3/2017 | 17/6/2026 | An issue was discovered in ytnef before 1.9.2. There is a potential heap-based buffer over-read on incoming Compressed RTF Streams, related to DecompressRTF() in libytnef. | |
| Modificada | Alta (7.5) | 1.9% | — | Ytnef Project YtnefDebian Linux | 10/3/2017 | 17/6/2026 | An issue was discovered in ytnef before 1.9.2. There is a potential out-of-bounds access with fields of Size 0 in TNEFParse() in libytnef. | |
| Modificada | Alta (7.5) | 1.7% | — | Ytnef Project YtnefDebian Linux | 10/3/2017 | 17/6/2026 | An issue was discovered in ytnef before 1.9.2. An invalid memory access (heap-based buffer over-read) can occur during handling of LONG data types, related to MAPIPrint() in libytnef. | |
| Modificada | Alta (7.8) | 1.4% | — | Tnef Project TnefDebian Linux | 24/2/2017 | 17/6/2026 | An issue was discovered in tnef before 1.4.13. Four type confusions have been identified in the file_add_mapi_attrs() function. These might lead to invalid read and write operations, controlled by an attacker. | |
| Modificada | Alta (7.8) | 1.4% | — | Tnef Project TnefDebian Linux | 24/2/2017 | 17/6/2026 | An issue was discovered in tnef before 1.4.13. Two type confusions have been identified in the parse_file() function. These might lead to invalid read and write operations, controlled by an attacker. | |
| Modificada | Alta (7.8) | 1.5% | — | Tnef Project TnefDebian Linux | 24/2/2017 | 17/6/2026 | An issue was discovered in tnef before 1.4.13. Several Integer Overflows, which can lead to Heap Overflows, have been identified in the functions that wrap memory allocation. |