Vulnerabilities
Vulnerable Software
Security Vulnerabilities
A flaw was found in tnef. A remote attacker could exploit this vulnerability by providing a specially crafted Transport Neutral Encapsulation Format (TNEF) file containing multiple message bodies. During extraction, improper memory management triggers a use-after-free and double-free condition, causing the application to crash and resulting in a Denial of Service (DoS).
CVSS Score
6.5
EPSS Score
0.003
Published
2026-10-01
A flaw was found in tnef. A heap-based buffer overflow can occur in the find_free_number() function when generating numbered backup suffixes for duplicate filenames. When numbered backups are enabled and file overwriting is disabled, an attacker can supply a specially crafted Transport Neutral Encapsulation Format (TNEF) file with an excessive number of colliding attachment filenames, causing the numeric counter to write past the allocated memory buffer. This issue may result in an application crash, leading to a Denial of Service (DoS), or potentially arbitrary code execution.
CVSS Score
3.1
EPSS Score
0.003
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs
CVSS Score
4.3
EPSS Score
0.002
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications
CVSS Score
5.4
EPSS Score
0.001
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration
CVSS Score
5.5
EPSS Score
0.002
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues
CVSS Score
6.5
EPSS Score
0.002
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments
CVSS Score
6.5
EPSS Score
0.007
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible
CVSS Score
8.1
EPSS Score
0.002
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes
CVSS Score
6.6
EPSS Score
0.002
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible
CVSS Score
2.0
EPSS Score
0.001
Published
2026-10-01


Contact Us

Shodan ® - All rights reserved