Catdoc v0.95 was discovered to contain a global buffer overflow via the function process_file at /src/reader.c.