Vulnerabilities > Ytnef Project

DATE CVE VULNERABILITY TITLE RISK
2019-10-29 CVE-2009-3887 Path Traversal vulnerability in Ytnef Project Ytnef
ytnef has directory traversal
network
low complexity
ytnef-project CWE-22
7.5
2017-08-02 CVE-2017-12144 Allocation of Resources Without Limits OR Throttling vulnerability in Ytnef Project Ytnef 1.9.2
In ytnef 1.9.2, an allocation failure was found in the function TNEFFillMapi in ytnef.c, which allows attackers to cause a denial of service via a crafted file.
4.3
2017-08-02 CVE-2017-12142 Out-Of-Bounds Read vulnerability in Ytnef Project Ytnef 1.9.2
In ytnef 1.9.2, an invalid memory read vulnerability was found in the function SwapDWord in ytnef.c, which allows attackers to cause a denial of service via a crafted file.
4.3
2017-08-02 CVE-2017-12141 Buffer Errors vulnerability in Ytnef Project Ytnef 1.9.2
In ytnef 1.9.2, a heap-based buffer overflow vulnerability was found in the function TNEFFillMapi in ytnef.c, which allows attackers to cause a denial of service via a crafted file.
4.3
2017-06-07 CVE-2017-9474 Out-Of-Bounds Read vulnerability in Ytnef Project Ytnef 1.9.2
In ytnef 1.9.2, the DecompressRTF function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
4.3
2017-06-07 CVE-2017-9473 In ytnef 1.9.2, the TNEFFillMapi function in lib/ytnef.c allows remote attackers to cause a denial of service (memory consumption) via a crafted file. 4.3
2017-06-07 CVE-2017-9472 Out-Of-Bounds Read vulnerability in Ytnef Project Ytnef 1.9.2
In ytnef 1.9.2, the SwapDWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
4.3
2017-06-07 CVE-2017-9471 Out-Of-Bounds Read vulnerability in multiple products
In ytnef 1.9.2, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
4.3
2017-06-07 CVE-2017-9470 Null Pointer Dereference vulnerability in Ytnef Project Ytnef 1.9.2
In ytnef 1.9.2, the MAPIPrint function in lib/ytnef.c allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.
4.3
2017-05-22 CVE-2017-9146 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Ytnef Project Ytnef
The TNEFFillMapi function in lib/ytnef.c in libytnef in ytnef through 1.9.2 does not ensure a nonzero count value before a certain memory allocation, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted tnef file.
6.8