CVE Tools

Ytnef-project

17 CVEs tracked since 2017. Since Feb 2017, none of them reached CISA KEV.

Ytnef-project CVEs per month

Feb 2017 to Aug 2017. Point at a month, or focus the strip and use the arrow keys.
Ytnef-project CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2017-0290
2017-0330
2017-04null or fewer
2017-0520
2017-06null or fewer
2017-07null or fewer
2017-0830

Products

The products that kept showing up in Ytnef-project's monthly top three, with their CVEs summed over those months.

  1. Ytnef174 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Ytnef-project.

  1. CVE-2009-3721Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications ...7.8
  2. CVE-2021-3404In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a heap buffer overflow which can be triggered via a...7.8
  3. CVE-2021-3403In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a double free which can be triggered via ...7.8
  4. CVE-2009-3887ytnef has directory traversal9.8
  5. CVE-2017-12144In ytnef 1.9.2, an allocation failure was found in the function TNEFFillMapi in ytnef.c, which allows attackers to cause a denial of service via a crafted file.5.5
  6. CVE-2017-12142In ytnef 1.9.2, an invalid memory read vulnerability was found in the function SwapDWord in ytnef.c, which allows attackers to cause a denial of service via a crafted file.5.5
  7. CVE-2017-12141In ytnef 1.9.2, a heap-based buffer overflow vulnerability was found in the function TNEFFillMapi in ytnef.c, which allows attackers to cause a denial of service via a crafted file.5.5
  8. CVE-2017-9474In ytnef 1.9.2, the DecompressRTF function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.5.5
  9. CVE-2017-9470In ytnef 1.9.2, the MAPIPrint function in lib/ytnef.c allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.5.5
  10. CVE-2017-9473In ytnef 1.9.2, the TNEFFillMapi function in lib/ytnef.c allows remote attackers to cause a denial of service (memory consumption) via a crafted file.5.5
  11. CVE-2017-9471In ytnef 1.9.2, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.5.5
  12. CVE-2017-9472In ytnef 1.9.2, the SwapDWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.5.5
  13. CVE-2017-9146The TNEFFillMapi function in lib/ytnef.c in libytnef in ytnef through 1.9.2 does not ensure a nonzero count value before a certain memory allocation, which allows remote attackers to cause a denial...8.8
  14. CVE-2017-9058In libytnef in ytnef through 1.9.2, there is a heap-based buffer over-read due to incorrect boundary checking in the SIZECHECK macro in lib/ytnef.c.9.8
  15. CVE-2017-6801An issue was discovered in ytnef before 1.9.2. There is a potential out-of-bounds access with fields of Size 0 in TNEFParse() in libytnef.7.5

The record

Peak rank
#29 in Feb 2017
Busiest month shown
Feb 2017, 9 CVEs
Months with a KEV entry
0 since Feb 2017
Monthly snapshots
4 since 2017
Ytnef-project's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store