Vulnerability Details CVE-2026-103679
A flaw was found in tnef. A remote attacker could exploit this vulnerability by providing a specially crafted Transport Neutral Encapsulation Format (TNEF) file containing multiple message bodies. During extraction, improper memory management triggers a use-after-free and double-free condition, causing the application to crash and resulting in a Denial of Service (DoS).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 20.2%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-103679
-
cpe:2.3:a:tnef_project:tnef:1.4.10
-
cpe:2.3:a:tnef_project:tnef:1.4.11
-
cpe:2.3:a:tnef_project:tnef:1.4.12
-
cpe:2.3:a:tnef_project:tnef:1.4.13
-
cpe:2.3:a:tnef_project:tnef:1.4.14
-
cpe:2.3:a:tnef_project:tnef:1.4.15
-
cpe:2.3:a:tnef_project:tnef:1.4.16
-
cpe:2.3:a:tnef_project:tnef:1.4.17
-
cpe:2.3:a:tnef_project:tnef:1.4.18