Tnef Project Tnef vulnerabilities
6 known vulnerabilities affecting tnef_project/tnef.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2019-18849MEDIUMCVSS 5.5fixed in 1.4.182019-11-11
CVE-2019-18849 [MEDIUM] CWE-125 CVE-2019-18849: In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file vi
In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup.
nvdosv
CVE-2017-8911CRITICALCVSS 9.8v1.4.142017-05-12
CVE-2017-8911 [CRITICAL] CWE-191 CVE-2017-8911: An integer underflow has been identified in the unicode_to_utf8() function in tnef 1.4.14. This migh
An integer underflow has been identified in the unicode_to_utf8() function in tnef 1.4.14. This might lead to invalid write operations, controlled by an attacker.
nvdosv
CVE-2017-6310HIGHCVSS 7.8≤ 1.4.122017-02-24
CVE-2017-6310 [HIGH] CWE-125 CVE-2017-6310: An issue was discovered in tnef before 1.4.13. Four type confusions have been identified in the file
An issue was discovered in tnef before 1.4.13. Four type confusions have been identified in the file_add_mapi_attrs() function. These might lead to invalid read and write operations, controlled by an attacker.
nvdosv
CVE-2017-6307HIGHCVSS 7.8≤ 1.4.122017-02-24
CVE-2017-6307 [HIGH] CWE-787 CVE-2017-6307: An issue was discovered in tnef before 1.4.13. Two OOB Writes have been identified in src/mapi_attr.
An issue was discovered in tnef before 1.4.13. Two OOB Writes have been identified in src/mapi_attr.c:mapi_attr_read(). These might lead to invalid read and write operations, controlled by an attacker.
nvdosv
CVE-2017-6309HIGHCVSS 7.8≤ 1.4.122017-02-24
CVE-2017-6309 [HIGH] CWE-125 CVE-2017-6309: An issue was discovered in tnef before 1.4.13. Two type confusions have been identified in the parse
An issue was discovered in tnef before 1.4.13. Two type confusions have been identified in the parse_file() function. These might lead to invalid read and write operations, controlled by an attacker.
nvdosv
CVE-2017-6308HIGHCVSS 7.8≤ 1.4.122017-02-24
CVE-2017-6308 [HIGH] CWE-190 CVE-2017-6308: An issue was discovered in tnef before 1.4.13. Several Integer Overflows, which can lead to Heap Ove
An issue was discovered in tnef before 1.4.13. Several Integer Overflows, which can lead to Heap Overflows, have been identified in the functions that wrap memory allocation.
nvdosv