Unrtf-project
2 CVEs tracked since 2014. Since Dec 2014, none of them reached CISA KEV.
Unrtf-project CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2014-12 | 2 | 0 |
Products
The products that kept showing up in Unrtf-project's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 5 most recently published vulnerabilities affecting Unrtf-project.
- CVE-2025-65411A NULL pointer dereference in the src/path.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the search_path parameter.7.5
- CVE-2025-65410A stack overflow in the src/main.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) via injecting a crafted input into the filename parameter.6.2
- CVE-2016-10091Multiple stack-based buffer overflows in unrtf 0.21.9 allow remote attackers to cause a denial-of-service by writing a negative integer to the (1) cmd_expand function, (2) cmd_emboss function, or (...7.5
- CVE-2014-9275UnRTF allows remote attackers to cause a denial of service (out-of-bounds memory access and crash) and possibly execute arbitrary code via a crafted RTF file.7.5
- CVE-2014-9274UnRTF allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code as demonstrated by a file containing the string "{\cb-999999999".7.5
The record
- Peak rank
- #100 in Dec 2014
- Busiest month shown
- Dec 2014, 2 CVEs
- Months with a KEV entry
- 0 since Dec 2014
- Monthly snapshots
- 1 since 2014