İçeriğe atla
Noroxi

tug kayıtları

tug üreticisine ait 19 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
8
Düzeltme kaydı olan
%84,2
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

19 kayıt
  • CVE-2016-10243
    41Planlayın

    TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf co

    KritikCVSS 9,8İstismar yokEPSS %7

    debian · debian linux2 May 2017

  • CVE-2017-17513
    35İzleyin

    TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might

    YüksekCVSS 8,8İstismar yokEPSS %1

    tug · tex live14 Ara 2017

  • CVE-2010-2642
    34İzleyin

    Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possi

    YüksekCVSS 7,6İstismar yokEPSS %14

    t1lib · t1lib7 Oca 2011

  • CVE-2018-17407
    32İzleyin

    An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21.

    YüksekCVSS 7,8İstismar yokEPSS %2

    tug · tex live23 Eyl 2018

  • CVE-2024-25262
    32İzleyin

    texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump.

    YüksekCVSS 8,1İstismar yokEPSS %1

    28 Şub 2024

  • CVE-2023-32700
    31İzleyin

    LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source.

    YüksekCVSS 7,8İstismar yokEPSS %1

    luatex project · luatex20 May 2023

  • CVE-2010-0739
    28İzleyin

    Integer overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote attacke

    OrtaCVSS 6,8İstismar yokEPSS %5

    tug · tetex16 Nis 2010

  • CVE-2010-0827
    28İzleyin

    Integer overflow in dvips in TeX Live 2009 and earlier, and teTeX, allows remote attackers to cause a denial of service (application crash)

    OrtaCVSS 6,8İstismar yokEPSS %4

    tug · tex live7 May 2010

  • CVE-2007-5935
    28İzleyin

    Stack-based buffer overflow in hpc.c in dvips in teTeX and TeXlive 2007 and earlier allows user-assisted attackers to execute arbitrary code

    OrtaCVSS 6,8İstismar yokEPSS %4

    tetex · tetex13 Kas 2007

  • CVE-2010-1440
    28İzleyin

    Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial

    OrtaCVSS 6,8İstismar yokEPSS %3

    tug · tetex7 May 2010

  • CVE-2007-5937
    28İzleyin

    Multiple buffer overflows in dvi2xx.c in dviljk in teTeX and TeXlive 2007 and earlier might allow user-assisted attackers to execute arbitra

    OrtaCVSS 6,8İstismar yokEPSS %3

    tetex · tetex13 Kas 2007

  • CVE-2015-5700
    24İzleyin

    mktexlsr revision 22855 through revision 36625 as packaged in texlive allows local users to write to arbitrary files via a symlink attack.

    OrtaCVSS 6,1İstismar yokEPSS %0

    tug · texlive25 Ağu 2017

  • CVE-2015-5701
    24İzleyin

    mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files via a symlink attac

    OrtaCVSS 6,1İstismar yokEPSS %0

    tug · texlive25 Ağu 2017

  • CVE-2023-46048
    24İzleyin

    Tex Live 944e257 has a NULL pointer dereference in texk/web2c/pdftexdir/writet1.c.

    OrtaCVSS 6,2İstismar yokEPSS %0

    27 Mar 2024

  • CVE-2023-32668
    22İzleyin

    LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests.

    OrtaCVSS 5,5İstismar yokEPSS %0

    luatex project · luatex11 May 2023

  • CVE-2010-0829
    18İzleyin

    Multiple array index errors in set.c in dvipng 1.11 and 1.12, and teTeX, allow remote attackers to cause a denial of service (application cr

    OrtaCVSS 4,3İstismar yokEPSS %5

    jan-ake larsson · dvipng7 May 2010

  • CVE-2007-5940
    18İzleyin

    feynmf.pl in feynmf 1.08, as used in TeXLive 2007, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink

    OrtaCVSS 4,6İstismar yokEPSS %0

    tug · texlive 200713 Kas 2007

  • CVE-2015-0296
    18İzleyin

    The pre-install script in texlive 3.1.20140525_r34255.fc21 as packaged in Fedora 21 and rpm, and texlive 6.20131226_r32488.fc20 and rpm allo

    OrtaCVSS 4,7İstismar yokEPSS %0

    tug · texlive6 Eki 2017

  • CVE-2007-5936
    14İzleyin

    dvips in teTeX and TeXlive 2007 and earlier allows local users to obtain sensitive information and modify certain data by creating certain t

    DüşükCVSS 3,6İstismar yokEPSS %0

    tetex · tetex13 Kas 2007