CVE-2009-3721 describes multiple directory traversal and buffer overflow vulnerabilities within yTNEF and Evolution's TNEF parser. These flaws allow a specially crafted email to write data to arbitrary file system locations, cause application crashes, or potentially execute arbitrary code when processing attachments in affected versions of GNOME Evolution and yTNEF. Rated with a CVSS score of 7.8 (High), successful exploitation requires user interaction (opening a malicious email) but has a low attack complexity, leading to high impacts on confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this decade-old vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:gnome:evolution:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:ytnef_project:ytnef:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.