A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text…

cve CVE-2026-103678 2 sources, 2 claims · Watch

NVD writes:
A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in get_rtf_data_from_buf(), reading beyond the allocated memory occurs. This flaw can cause the application to crash, leading to a Denial of Service (DoS), or leak sensitive memory contents into extracted output files. the claim
Severity they disagree
medium GitHub advisories
HIGH NVD
CVSS they disagree
5.4 GitHub advisories
8.1 NVD
CWE
CWE-125 GitHub advisories
CWE-125 NVD

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild
  6. Used in ransomware campaigns

Timeline

2026-10-01first spoke of it: A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially...GitHub advisories
2026-10-01first spoke of it: A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in get_rtf_data_from_buf(), reading beyond the allocated memory occurs. This flaw can cause the application to crash, leading to a Denial of Service (DoS), or leak sensitive memory contents into extracted output files.NVD

A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in get_rtf_data_from_buf(), reading beyond the allocated memory occurs. This flaw can cause the application to crash, leading to a Denial of Service (DoS), or leak sensitive memory contents into extracted output files.

What it is to other things

affectstnef_project/tnef
NVD
made_bytnef_project
NVD
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Automatable
automatable
NVDno
At least one of those steps needs a person.
receipt
Source
NVD
Its words
no
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].automatable
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCno
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://github.com/verdammelt/tnef",
            "defaultStatus": "unaffected",
            "packageName": "tnef",
            "versions": [
              {
                "lessThanOrEqual": "1.4.18",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "patrick@puiterwijk.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:tnef_project:tnef:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D0971079-1960-4691-BA33-FDECDAAB7233",
                "versionEndIncluding": "1.4.18",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in get_rtf_data_from_buf(), reading beyond the allocated memory occurs. This flaw can cause the application to crash, leading to a Denial of Service (DoS), or leak sensitive memory contents into extracted output files."
      }
    ],
    "id": "CVE-2026-103678",
    "lastModified": "2026-10-05T14:25:05.183",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "patrick@puiterwijk.org",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-103678",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-01T15:00:11.354180Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-10-01T12:17:15.557",
    "references": [
      {
        "source": "patrick@puiterwijk.org",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2026-103678"
      },
      {
        "source": "patrick@puiterwijk.org",
        "tags": [
          "Issue Tracking",
          "Third Party Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2544476"
      },
      {
        "source": "patrick@puiterwijk.org",
        "tags": [
          "Product"
        ],
        "url": "https://github.com/verdammelt/tnef"
      }
    ],
    "sourceIdentifier": "patrick@puiterwijk.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-125"
          }
        ],
        "source": "patrick@puiterwijk.org",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
conflict
GitHub advisories5.4
receipt
Source
GitHub advisories
Its words
5.4
Read by
field:cvss.score
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-103678",
  "cvss": {
    "score": 5.4,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 5.4,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-125",
      "name": "Out-of-bounds Read"
    }
  ],
  "description": "A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in get_rtf_data_from_buf(), reading beyond the allocated memory occurs. This flaw can cause the application to crash, leading to a Denial of Service (DoS), or leak sensitive memory contents into extracted output files.",
  "ghsa_id": "GHSA-8r4j-263j-fh85",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-8r4j-263j-fh85",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-8r4j-263j-fh85"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-103678"
    }
  ],
  "nvd_published_at": "2026-10-01T12:17:15Z",
  "published_at": "2026-10-01T12:31:20Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-103678",
    "https://access.redhat.com/security/cve/CVE-2026-103678",
    "https://bugzilla.redhat.com/show_bug.cgi?id=2544476",
    "https://github.com/verdammelt/tnef",
    "https://github.com/advisories/GHSA-8r4j-263j-fh85"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially...",
  "type": "unreviewed",
  "updated_at": "2026-10-01T12:31:28Z",
  "url": "https://api.github.com/advisories/GHSA-8r4j-263j-fh85",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
CVSS
cvss
conflict
NVD8.1
receipt
Source
NVD
Its words
8.1
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-06 11:32 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:32 UTC8.1
2026-10-02 12:00 UTC5.4
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://github.com/verdammelt/tnef",
            "defaultStatus": "unaffected",
            "packageName": "tnef",
            "versions": [
              {
                "lessThanOrEqual": "1.4.18",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "patrick@puiterwijk.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:tnef_project:tnef:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D0971079-1960-4691-BA33-FDECDAAB7233",
                "versionEndIncluding": "1.4.18",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in get_rtf_data_from_buf(), reading beyond the allocated memory occurs. This flaw can cause the application to crash, leading to a Denial of Service (DoS), or leak sensitive memory contents into extracted output files."
      }
    ],
    "id": "CVE-2026-103678",
    "lastModified": "2026-10-05T14:25:05.183",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "patrick@puiterwijk.org",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-103678",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-01T15:00:11.354180Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-10-01T12:17:15.557",
    "references": [
      {
        "source": "patrick@puiterwijk.org",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2026-103678"
      },
      {
        "source": "patrick@puiterwijk.org",
        "tags": [
          "Issue Tracking",
          "Third Party Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2544476"
      },
      {
        "source": "patrick@puiterwijk.org",
        "tags": [
          "Product"
        ],
        "url": "https://github.com/verdammelt/tnef"
      }
    ],
    "sourceIdentifier": "patrick@puiterwijk.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-125"
          }
        ],
        "source": "patrick@puiterwijk.org",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
NVDCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
receipt
Source
NVD
Its words
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://github.com/verdammelt/tnef",
            "defaultStatus": "unaffected",
            "packageName": "tnef",
            "versions": [
              {
                "lessThanOrEqual": "1.4.18",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "patrick@puiterwijk.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:tnef_project:tnef:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D0971079-1960-4691-BA33-FDECDAAB7233",
                "versionEndIncluding": "1.4.18",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in get_rtf_data_from_buf(), reading beyond the allocated memory occurs. This flaw can cause the application to crash, leading to a Denial of Service (DoS), or leak sensitive memory contents into extracted output files."
      }
    ],
    "id": "CVE-2026-103678",
    "lastModified": "2026-10-05T14:25:05.183",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "patrick@puiterwijk.org",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-103678",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-01T15:00:11.354180Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-10-01T12:17:15.557",
    "references": [
      {
        "source": "patrick@puiterwijk.org",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2026-103678"
      },
      {
        "source": "patrick@puiterwijk.org",
        "tags": [
          "Issue Tracking",
          "Third Party Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2544476"
      },
      {
        "source": "patrick@puiterwijk.org",
        "tags": [
          "Product"
        ],
        "url": "https://github.com/verdammelt/tnef"
      }
    ],
    "sourceIdentifier": "patrick@puiterwijk.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-125"
          }
        ],
        "source": "patrick@puiterwijk.org",
        "type": "Secondary"
      }
    ]
  }
}
—
CWE
cwe
GitHub advisoriesCWE-125
receipt
Source
GitHub advisories
Its words
CWE-125
Read by
field:cwes[].cwe_id
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-103678",
  "cvss": {
    "score": 5.4,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 5.4,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-125",
      "name": "Out-of-bounds Read"
    }
  ],
  "description": "A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in get_rtf_data_from_buf(), reading beyond the allocated memory occurs. This flaw can cause the application to crash, leading to a Denial of Service (DoS), or leak sensitive memory contents into extracted output files.",
  "ghsa_id": "GHSA-8r4j-263j-fh85",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-8r4j-263j-fh85",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-8r4j-263j-fh85"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-103678"
    }
  ],
  "nvd_published_at": "2026-10-01T12:17:15Z",
  "published_at": "2026-10-01T12:31:20Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-103678",
    "https://access.redhat.com/security/cve/CVE-2026-103678",
    "https://bugzilla.redhat.com/show_bug.cgi?id=2544476",
    "https://github.com/verdammelt/tnef",
    "https://github.com/advisories/GHSA-8r4j-263j-fh85"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially...",
  "type": "unreviewed",
  "updated_at": "2026-10-01T12:31:28Z",
  "url": "https://api.github.com/advisories/GHSA-8r4j-263j-fh85",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
CWE
cwe
NVDCWE-125
receipt
Source
NVD
Its words
CWE-125
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCCWE-125
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://github.com/verdammelt/tnef",
            "defaultStatus": "unaffected",
            "packageName": "tnef",
            "versions": [
              {
                "lessThanOrEqual": "1.4.18",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "patrick@puiterwijk.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:tnef_project:tnef:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D0971079-1960-4691-BA33-FDECDAAB7233",
                "versionEndIncluding": "1.4.18",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in get_rtf_data_from_buf(), reading beyond the allocated memory occurs. This flaw can cause the application to crash, leading to a Denial of Service (DoS), or leak sensitive memory contents into extracted output files."
      }
    ],
    "id": "CVE-2026-103678",
    "lastModified": "2026-10-05T14:25:05.183",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "patrick@puiterwijk.org",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-103678",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-01T15:00:11.354180Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-10-01T12:17:15.557",
    "references": [
      {
        "source": "patrick@puiterwijk.org",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2026-103678"
      },
      {
        "source": "patrick@puiterwijk.org",
        "tags": [
          "Issue Tracking",
          "Third Party Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2544476"
      },
      {
        "source": "patrick@puiterwijk.org",
        "tags": [
          "Product"
        ],
        "url": "https://github.com/verdammelt/tnef"
      }
    ],
    "sourceIdentifier": "patrick@puiterwijk.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-125"
          }
        ],
        "source": "patrick@puiterwijk.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Exploitation
exploitation
NVDnone
No evidence of exploitation, and no public proof of concept.
receipt
Source
NVD
Its words
none
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].exploitation
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCnone
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://github.com/verdammelt/tnef",
            "defaultStatus": "unaffected",
            "packageName": "tnef",
            "versions": [
              {
                "lessThanOrEqual": "1.4.18",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "patrick@puiterwijk.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:tnef_project:tnef:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D0971079-1960-4691-BA33-FDECDAAB7233",
                "versionEndIncluding": "1.4.18",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in get_rtf_data_from_buf(), reading beyond the allocated memory occurs. This flaw can cause the application to crash, leading to a Denial of Service (DoS), or leak sensitive memory contents into extracted output files."
      }
    ],
    "id": "CVE-2026-103678",
    "lastModified": "2026-10-05T14:25:05.183",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "patrick@puiterwijk.org",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-103678",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-01T15:00:11.354180Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-10-01T12:17:15.557",
    "references": [
      {
        "source": "patrick@puiterwijk.org",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2026-103678"
      },
      {
        "source": "patrick@puiterwijk.org",
        "tags": [
          "Issue Tracking",
          "Third Party Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2544476"
      },
      {
        "source": "patrick@puiterwijk.org",
        "tags": [
          "Product"
        ],
        "url": "https://github.com/verdammelt/tnef"
      }
    ],
    "sourceIdentifier": "patrick@puiterwijk.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-125"
          }
        ],
        "source": "patrick@puiterwijk.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
conflict
GitHub advisoriesmedium
receipt
Source
GitHub advisories
Its words
medium
Read by
field:severity
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-103678",
  "cvss": {
    "score": 5.4,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 5.4,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L"
    },
    "cvss_v4": {
      "score": 0.0,
      "vector_string": null
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-125",
      "name": "Out-of-bounds Read"
    }
  ],
  "description": "A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in get_rtf_data_from_buf(), reading beyond the allocated memory occurs. This flaw can cause the application to crash, leading to a Denial of Service (DoS), or leak sensitive memory contents into extracted output files.",
  "ghsa_id": "GHSA-8r4j-263j-fh85",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-8r4j-263j-fh85",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-8r4j-263j-fh85"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-103678"
    }
  ],
  "nvd_published_at": "2026-10-01T12:17:15Z",
  "published_at": "2026-10-01T12:31:20Z",
  "references": [
    "https://nvd.nist.gov/vuln/detail/CVE-2026-103678",
    "https://access.redhat.com/security/cve/CVE-2026-103678",
    "https://bugzilla.redhat.com/show_bug.cgi?id=2544476",
    "https://github.com/verdammelt/tnef",
    "https://github.com/advisories/GHSA-8r4j-263j-fh85"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially...",
  "type": "unreviewed",
  "updated_at": "2026-10-01T12:31:28Z",
  "url": "https://api.github.com/advisories/GHSA-8r4j-263j-fh85",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Severity
severity
conflict
NVDHIGH
From 7.0 to 8.9.
receipt
Source
NVD
Its words
HIGH
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCHIGH
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://github.com/verdammelt/tnef",
            "defaultStatus": "unaffected",
            "packageName": "tnef",
            "versions": [
              {
                "lessThanOrEqual": "1.4.18",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "patrick@puiterwijk.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:tnef_project:tnef:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D0971079-1960-4691-BA33-FDECDAAB7233",
                "versionEndIncluding": "1.4.18",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in get_rtf_data_from_buf(), reading beyond the allocated memory occurs. This flaw can cause the application to crash, leading to a Denial of Service (DoS), or leak sensitive memory contents into extracted output files."
      }
    ],
    "id": "CVE-2026-103678",
    "lastModified": "2026-10-05T14:25:05.183",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "patrick@puiterwijk.org",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-103678",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-01T15:00:11.354180Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-10-01T12:17:15.557",
    "references": [
      {
        "source": "patrick@puiterwijk.org",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2026-103678"
      },
      {
        "source": "patrick@puiterwijk.org",
        "tags": [
          "Issue Tracking",
          "Third Party Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2544476"
      },
      {
        "source": "patrick@puiterwijk.org",
        "tags": [
          "Product"
        ],
        "url": "https://github.com/verdammelt/tnef"
      }
    ],
    "sourceIdentifier": "patrick@puiterwijk.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-125"
          }
        ],
        "source": "patrick@puiterwijk.org",
        "type": "Secondary"
      }
    ]
  }
}
high
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-10-05 18:25 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-05 18:25 UTCAnalyzed
2026-10-02 12:00 UTCUndergoing Analysis
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://github.com/verdammelt/tnef",
            "defaultStatus": "unaffected",
            "packageName": "tnef",
            "versions": [
              {
                "lessThanOrEqual": "1.4.18",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "patrick@puiterwijk.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:tnef_project:tnef:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D0971079-1960-4691-BA33-FDECDAAB7233",
                "versionEndIncluding": "1.4.18",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in get_rtf_data_from_buf(), reading beyond the allocated memory occurs. This flaw can cause the application to crash, leading to a Denial of Service (DoS), or leak sensitive memory contents into extracted output files."
      }
    ],
    "id": "CVE-2026-103678",
    "lastModified": "2026-10-05T14:25:05.183",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "patrick@puiterwijk.org",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-103678",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-01T15:00:11.354180Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-10-01T12:17:15.557",
    "references": [
      {
        "source": "patrick@puiterwijk.org",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2026-103678"
      },
      {
        "source": "patrick@puiterwijk.org",
        "tags": [
          "Issue Tracking",
          "Third Party Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2544476"
      },
      {
        "source": "patrick@puiterwijk.org",
        "tags": [
          "Product"
        ],
        "url": "https://github.com/verdammelt/tnef"
      }
    ],
    "sourceIdentifier": "patrick@puiterwijk.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-125"
          }
        ],
        "source": "patrick@puiterwijk.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Technical impact
technical_impact
NVDpartial
The attacker gains limited control, or limited information.
receipt
Source
NVD
Its words
partial
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].technicalImpact
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCpartial
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "collectionURL": "https://github.com/verdammelt/tnef",
            "defaultStatus": "unaffected",
            "packageName": "tnef",
            "versions": [
              {
                "lessThanOrEqual": "1.4.18",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "patrick@puiterwijk.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:tnef_project:tnef:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "D0971079-1960-4691-BA33-FDECDAAB7233",
                "versionEndIncluding": "1.4.18",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in get_rtf_data_from_buf(), reading beyond the allocated memory occurs. This flaw can cause the application to crash, leading to a Denial of Service (DoS), or leak sensitive memory contents into extracted output files."
      }
    ],
    "id": "CVE-2026-103678",
    "lastModified": "2026-10-05T14:25:05.183",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 2.5,
          "source": "patrick@puiterwijk.org",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 5.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-103678",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-01T15:00:11.354180Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-10-01T12:17:15.557",
    "references": [
      {
        "source": "patrick@puiterwijk.org",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://access.redhat.com/security/cve/CVE-2026-103678"
      },
      {
        "source": "patrick@puiterwijk.org",
        "tags": [
          "Issue Tracking",
          "Third Party Advisory"
        ],
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2544476"
      },
      {
        "source": "patrick@puiterwijk.org",
        "tags": [
          "Product"
        ],
        "url": "https://github.com/verdammelt/tnef"
      }
    ],
    "sourceIdentifier": "patrick@puiterwijk.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-125"
          }
        ],
        "source": "patrick@puiterwijk.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. Because the application fails to properly validate input buffer boundaries before copying data in get_rtf_data_from_buf(), reading beyond the allocated memory occurs. This flaw can cause the application to crash, leading to a Denial of Service (DoS), or leak sensitive memory contents into extracted output files.
zetlyn/cve-nvd · 2026-10-01
automatable no cvss 8.1 cvss_vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H cwe CWE-125 exploitation none severity HIGH status Analyzed technical_impact partial source
A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially...
zetlyn/cve-ghsa · 2026-10-01
cvss 5.4 cwe CWE-125 severity medium source