The Tnef Project maintains a specialized utility for parsing and extracting content from TNEF (Transport Neutral Encapsulation Format) files, a niche but recurrent component in email processing pipelines. Vulnerabilities affecting this tool skew toward serious outcomes, with a meaningful share reaching critical severity, and concentrate through memory-safety and integer-handling weakness classes including out-of-bounds reads and writes, integer overflows, and integer underflows that reflect the parsing demands of binary format processing. Defenders should treat updates to this library as relevant wherever TNEF handling is performed, particularly in mail servers and gateways; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tnef Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-8911CRITICAL An integer underflow has been identified in the unicode_to_utf8() function in tnef 1.4.14. This might lead to invalid write operations, controlled by an attacker. | May 12, 2017 | 9.8 | 31 | NO | NO |
CVE-2017-6310HIGH An issue was discovered in tnef before 1.4.13. Four type confusions have been identified in the file_add_mapi_attrs() function. These might lead to invalid read and write operation | Feb 24, 2017 | 7.8 | 24 | NO | NO |
CVE-2017-6309HIGH An issue was discovered in tnef before 1.4.13. Two type confusions have been identified in the parse_file() function. These might lead to invalid read and write operations, control | Feb 24, 2017 | 7.8 | 24 | NO | NO |
CVE-2017-6308HIGH An issue was discovered in tnef before 1.4.13. Several Integer Overflows, which can lead to Heap Overflows, have been identified in the functions that wrap memory allocation. | Feb 24, 2017 | 7.8 | 24 | NO | NO |
CVE-2017-6307HIGH An issue was discovered in tnef before 1.4.13. Two OOB Writes have been identified in src/mapi_attr.c:mapi_attr_read(). These might lead to invalid read and write operations, contr | Feb 24, 2017 | 7.8 | 23 | NO | NO |
CVE-2019-18849MEDIUM In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, b | Nov 11, 2019 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tnef Project.
Media articles that mention a CVE ID that affects a product developed by Tnef Project — matched by CVE ID, not by vendor name.