ytnef_project CVE Vulnerabilities & Metrics

Focus on ytnef_project vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About ytnef_project Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with ytnef_project. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total ytnef_project CVEs: 26
Earliest CVE date: 24 Feb 2017, 04:59 UTC
Latest CVE date: 26 May 2021, 22:15 UTC

Latest CVE reference: CVE-2009-3721

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical ytnef_project CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.78

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 0
4.0-6.9 24
7.0-8.9 2
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS ytnef_project CVEs

These are the five CVEs with the highest CVSS scores for ytnef_project, sorted by severity first and recency.

All CVEs for ytnef_project

CVE-2009-3721 ytnef_project vulnerability CVSS: 6.8 26 May 2021, 22:15 UTC

Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesystem, crash, or potentially execute arbitrary code when decoding attachments.

CVE-2021-3404 ytnef_project vulnerability CVSS: 6.8 04 Mar 2021, 22:15 UTC

In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a heap buffer overflow which can be triggered via a crafted file.

CVE-2021-3403 ytnef_project vulnerability CVSS: 6.8 04 Mar 2021, 22:15 UTC

In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a double free which can be triggered via a crafted file.

CVE-2009-3887 ytnef_project vulnerability CVSS: 7.5 29 Oct 2019, 19:15 UTC

ytnef has directory traversal

CVE-2017-12144 ytnef_project vulnerability CVSS: 4.3 02 Aug 2017, 05:29 UTC

In ytnef 1.9.2, an allocation failure was found in the function TNEFFillMapi in ytnef.c, which allows attackers to cause a denial of service via a crafted file.

CVE-2017-12142 ytnef_project vulnerability CVSS: 4.3 02 Aug 2017, 05:29 UTC

In ytnef 1.9.2, an invalid memory read vulnerability was found in the function SwapDWord in ytnef.c, which allows attackers to cause a denial of service via a crafted file.

CVE-2017-12141 ytnef_project vulnerability CVSS: 4.3 02 Aug 2017, 05:29 UTC

In ytnef 1.9.2, a heap-based buffer overflow vulnerability was found in the function TNEFFillMapi in ytnef.c, which allows attackers to cause a denial of service via a crafted file.

CVE-2017-9474 ytnef_project vulnerability CVSS: 4.3 07 Jun 2017, 05:29 UTC

In ytnef 1.9.2, the DecompressRTF function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.

CVE-2017-9473 ytnef_project vulnerability CVSS: 4.3 07 Jun 2017, 05:29 UTC

In ytnef 1.9.2, the TNEFFillMapi function in lib/ytnef.c allows remote attackers to cause a denial of service (memory consumption) via a crafted file.

CVE-2017-9472 ytnef_project vulnerability CVSS: 4.3 07 Jun 2017, 05:29 UTC

In ytnef 1.9.2, the SwapDWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.

CVE-2017-9471 ytnef_project vulnerability CVSS: 4.3 07 Jun 2017, 05:29 UTC

In ytnef 1.9.2, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.

CVE-2017-9470 ytnef_project vulnerability CVSS: 4.3 07 Jun 2017, 05:29 UTC

In ytnef 1.9.2, the MAPIPrint function in lib/ytnef.c allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.

CVE-2017-9146 ytnef_project vulnerability CVSS: 6.8 22 May 2017, 18:29 UTC

The TNEFFillMapi function in lib/ytnef.c in libytnef in ytnef through 1.9.2 does not ensure a nonzero count value before a certain memory allocation, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted tnef file.

CVE-2017-9058 ytnef_project vulnerability CVSS: 7.5 18 May 2017, 06:29 UTC

In libytnef in ytnef through 1.9.2, there is a heap-based buffer over-read due to incorrect boundary checking in the SIZECHECK macro in lib/ytnef.c.

CVE-2017-6802 ytnef_project vulnerability CVSS: 5.0 10 Mar 2017, 10:59 UTC

An issue was discovered in ytnef before 1.9.2. There is a potential heap-based buffer over-read on incoming Compressed RTF Streams, related to DecompressRTF() in libytnef.

CVE-2017-6801 ytnef_project vulnerability CVSS: 5.0 10 Mar 2017, 10:59 UTC

An issue was discovered in ytnef before 1.9.2. There is a potential out-of-bounds access with fields of Size 0 in TNEFParse() in libytnef.

CVE-2017-6800 ytnef_project vulnerability CVSS: 5.0 10 Mar 2017, 10:59 UTC

An issue was discovered in ytnef before 1.9.2. An invalid memory access (heap-based buffer over-read) can occur during handling of LONG data types, related to MAPIPrint() in libytnef.

CVE-2017-6306 ytnef_project vulnerability CVSS: 6.8 24 Feb 2017, 04:59 UTC

An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "9 of 9. Directory Traversal using the filename; SanitizeFilename function in settings.c."

CVE-2017-6305 ytnef_project vulnerability CVSS: 6.8 24 Feb 2017, 04:59 UTC

An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "8 of 9. Out of Bounds read and write."

CVE-2017-6304 ytnef_project vulnerability CVSS: 6.8 24 Feb 2017, 04:59 UTC

An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "7 of 9. Out of Bounds read."

CVE-2017-6303 ytnef_project vulnerability CVSS: 6.8 24 Feb 2017, 04:59 UTC

An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "6 of 9. Invalid Write and Integer Overflow."

CVE-2017-6302 ytnef_project vulnerability CVSS: 6.8 24 Feb 2017, 04:59 UTC

An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "5 of 9. Integer Overflow."

CVE-2017-6301 ytnef_project vulnerability CVSS: 6.8 24 Feb 2017, 04:59 UTC

An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "4 of 9. Out of Bounds Reads."

CVE-2017-6300 ytnef_project vulnerability CVSS: 6.8 24 Feb 2017, 04:59 UTC

An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "3 of 9. Buffer Overflow in version field in lib/tnef-types.h."

CVE-2017-6299 ytnef_project vulnerability CVSS: 4.3 24 Feb 2017, 04:59 UTC

An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "2 of 9. Infinite Loop / DoS in the TNEFFillMapi function in lib/ytnef.c."

CVE-2017-6298 ytnef_project vulnerability CVSS: 6.8 24 Feb 2017, 04:59 UTC

An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "1 of 9. Null Pointer Deref / calloc return value not checked."