Ytnef Project maintains a conversion utility that parses and extracts data from TNEF-formatted email attachments, a narrow but strategically positioned tool embedded in mail-processing pipelines and email clients across various platforms. Despite its focused scope, the project ranks prominently in vulnerability landscapes relative to similar utilities, reflecting its role in handling untrusted, binary-formatted input from external sources. Vulnerabilities affecting the project skew toward moderate-to-serious outcomes and recur across a set of memory-safety and input-validation weakness classes—out-of-bounds reads, buffer-boundary violations, path traversal, integer overflow, and NULL-pointer dereferences—that are characteristic of C-based parsers operating on adversary-controlled data. Defenders integrating or deploying this utility should treat parser-layer updates as meaningful and ensure it runs with appropriate sandboxing or privilege constraints; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ytnef Project over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9058CRITICAL In libytnef in ytnef through 1.9.2, there is a heap-based buffer over-read due to incorrect boundary checking in the SIZECHECK macro in lib/ytnef.c. | May 18, 2017 | 9.8 | 32 | NO | NO |
CVE-2009-3887CRITICAL ytnef has directory traversal | Oct 29, 2019 | 9.8 | 31 | NO | NO |
CVE-2017-9146HIGH The TNEFFillMapi function in lib/ytnef.c in libytnef in ytnef through 1.9.2 does not ensure a nonzero count value before a certain memory allocation, which allows remote attackers | May 22, 2017 | 8.8 | 28 | NO | NO |
CVE-2021-3404HIGH In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a heap buffer overflow which can b | Mar 4, 2021 | 7.8 | 25 | NO | NO |
CVE-2021-3403HIGH In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a double free which can | Mar 4, 2021 | 7.8 | 25 | NO | NO |
CVE-2017-6800HIGH An issue was discovered in ytnef before 1.9.2. An invalid memory access (heap-based buffer over-read) can occur during handling of LONG data types, related to MAPIPrint() in libytn | Mar 10, 2017 | 7.5 | 25 | NO | NO |
CVE-2009-3721HIGH Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause th | May 26, 2021 | 7.8 | 24 | NO | NO |
CVE-2017-6802HIGH An issue was discovered in ytnef before 1.9.2. There is a potential heap-based buffer over-read on incoming Compressed RTF Streams, related to DecompressRTF() in libytnef. | Mar 10, 2017 | 7.5 | 24 | NO | NO |
CVE-2017-6801HIGH An issue was discovered in ytnef before 1.9.2. There is a potential out-of-bounds access with fields of Size 0 in TNEFParse() in libytnef. | Mar 10, 2017 | 7.5 | 24 | NO | NO |
CVE-2017-6306HIGH An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "9 of 9. Directory Traversal using the filename; SanitizeFilename function in settings.c." | Feb 24, 2017 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ytnef Project.
Media articles that mention a CVE ID that affects a product developed by Ytnef Project — matched by CVE ID, not by vendor name.