
CVE-2016-10091
https://notcve.org/view.php?id=CVE-2016-10091
21 Apr 2017 — Multiple stack-based buffer overflows in unrtf 0.21.9 allow remote attackers to cause a denial-of-service by writing a negative integer to the (1) cmd_expand function, (2) cmd_emboss function, or (3) cmd_engrave function. Múltiples desbordamientos de búfer basado en pila en unrtf 0.21.9 permite a atacantes remotos provocar una denegación de servicio escribiendo un entero negativo en la función (1) cmd_expand, (2) función cmd_emboss o (3) cmd_engrave. • http://hg.savannah.gnu.org/hgweb/unrtf/rev/3b16893a6406 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2014-9274 – Mandriva Linux Security Advisory 2015-007
https://notcve.org/view.php?id=CVE-2014-9274
09 Dec 2014 — UnRTF allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code as demonstrated by a file containing the string "{\cb-999999999". UnRTF permite a atacantes remotos causar una denegación de servicio (caída) y posiblemente ejecutar código arbitrario tal y como fue demostrado por un fichero que contenía la cadena '{\cb-999999999'. Michal Zalewski reported an out-of-bounds memory access vulnerability in unrtf. Processing a malformed RTF file could lead to a segfault while ... • http://advisories.mageia.org/MGASA-2014-0533.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2014-9275 – Mandriva Linux Security Advisory 2015-026
https://notcve.org/view.php?id=CVE-2014-9275
09 Dec 2014 — UnRTF allows remote attackers to cause a denial of service (out-of-bounds memory access and crash) and possibly execute arbitrary code via a crafted RTF file. UnRTF permite a atacantes remotos causar una denegación de servicio (acceso a la memoria fuera de rango y caída) y posiblemente ejecutar código arbitrario a través de un fichero RTF manipulado. Michal Zalewski reported an out-of-bounds memory access vulnerability in unrtf. Processing a malformed RTF file could lead to a segfault while accessing a poin... • http://advisories.mageia.org/MGASA-2014-0533.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •