CVE-2016-10091
https://notcve.org/view.php?id=CVE-2016-10091
Multiple stack-based buffer overflows in unrtf 0.21.9 allow remote attackers to cause a denial-of-service by writing a negative integer to the (1) cmd_expand function, (2) cmd_emboss function, or (3) cmd_engrave function. Múltiples desbordamientos de búfer basado en pila en unrtf 0.21.9 permite a atacantes remotos provocar una denegación de servicio escribiendo un entero negativo en la función (1) cmd_expand, (2) función cmd_emboss o (3) cmd_engrave. • http://hg.savannah.gnu.org/hgweb/unrtf/rev/3b16893a6406 http://www.openwall.com/lists/oss-security/2016/12/31/3 http://www.openwall.com/lists/oss-security/2017/01/01/1 http://www.securityfocus.com/bid/95173 https://bugzilla.redhat.com/show_bug.cgi?id=1409546 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2014-9274
https://notcve.org/view.php?id=CVE-2014-9274
UnRTF allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code as demonstrated by a file containing the string "{\cb-999999999". UnRTF permite a atacantes remotos causar una denegación de servicio (caída) y posiblemente ejecutar código arbitrario tal y como fue demostrado por un fichero que contenía la cadena '{\cb-999999999'. • http://advisories.mageia.org/MGASA-2014-0533.html http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147399.html http://secunia.com/advisories/62811 http://www.debian.org/security/2015/dsa-3158 http://www.mandriva.com/security/advisories?name=MDVSA-2015:007 http://www.openwall.com/lists/oss-security/2014/12/04/15 http://www.securityfocus.com/bid/71430 https://bugzilla.redhat.com/show_bug.cgi?id=1170233 https://lists.gnu.org/archive/html/bug-unrtf/2014-1 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2014-9275
https://notcve.org/view.php?id=CVE-2014-9275
UnRTF allows remote attackers to cause a denial of service (out-of-bounds memory access and crash) and possibly execute arbitrary code via a crafted RTF file. UnRTF permite a atacantes remotos causar una denegación de servicio (acceso a la memoria fuera de rango y caída) y posiblemente ejecutar código arbitrario a través de un fichero RTF manipulado. • http://advisories.mageia.org/MGASA-2014-0533.html http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147399.html http://secunia.com/advisories/62811 http://www.debian.org/security/2015/dsa-3158 http://www.mandriva.com/security/advisories?name=MDVSA-2015:007 http://www.openwall.com/lists/oss-security/2014/12/03/4 http://www.openwall.com/lists/oss-security/2014/12/04/15 http://www.securityfocus.com/bid/71506 https://bugzilla.redhat.com/show_bug.cgi?id • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •