Integer overflows on multiple file formats ( TNEF, CHM, FSG) parsing lead to heap corruption.
vulners.com/securityvulns/securityvulns:doc:9282