VYPR

unrtf

by GNU

CVEs (3)

  • CVE-2025-65411HigDec 30, 2025
    risk 0.49cvss 7.5epss 0.01

    A NULL pointer dereference in the src/path.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) via injecting a crafted payload into the search_path parameter.

  • CVE-2016-10091HigApr 21, 2017
    risk 0.49cvss 7.5epss 0.03

    Multiple stack-based buffer overflows in unrtf 0.21.9 allow remote attackers to cause a denial-of-service by writing a negative integer to the (1) cmd_expand function, (2) cmd_emboss function, or (3) cmd_engrave function.

  • CVE-2025-65410MedDec 23, 2025
    risk 0.40cvss 6.2epss 0.00

    A stack overflow in the src/main.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) via injecting a crafted input into the filename parameter.