tug records
19 published records for vendor tug.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 8
- With a fix record
- 84.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer5
- CWE-59 Improper Link Resolution Before File Access ('Link Following')3
- CWE-189 Numeric Errors3
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-20 Improper Input Validation1
- CWE-476 NULL Pointer Dereference1
The weakness classes this vendor ships most often: where to look.
CWEAll records
19 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2016-10243No exploit | TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf codebian · debian linux · CWE-20 | Critical9.8 | — | 7.1% | May 2, 2017 |
35Monitor | CVE-2017-17513No exploit | TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might tug · tex live · CWE-74 | High8.8 | — | 1.3% | Dec 14, 2017 |
34Monitor | CVE-2010-2642No exploit | Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possit1lib · t1lib · CWE-119 | High7.6 | — | 14.3% | Jan 7, 2011 |
32Monitor | CVE-2018-17407No exploit | An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21.tug · tex live · CWE-119 | High7.8 | — | 2.1% | Sep 23, 2018 |
32Monitor | CVE-2024-25262No exploit | texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump.CWE-122 | High8.1 | — | 0.9% | Feb 28, 2024 |
31Monitor | CVE-2023-32700No exploit | LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source.luatex project · luatex · CWE-77 | High7.8 | — | 0.8% | May 20, 2023 |
28Monitor | CVE-2010-0739No exploit | Integer overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote attacketug · tetex · CWE-189 | Medium6.8 | — | 4.9% | Apr 16, 2010 |
28Monitor | CVE-2010-0827No exploit | Integer overflow in dvips in TeX Live 2009 and earlier, and teTeX, allows remote attackers to cause a denial of service (application crash) tug · tex live · CWE-189 | Medium6.8 | — | 4.4% | May 7, 2010 |
28Monitor | CVE-2007-5935No exploit | Stack-based buffer overflow in hpc.c in dvips in teTeX and TeXlive 2007 and earlier allows user-assisted attackers to execute arbitrary codetetex · tetex · CWE-119 | Medium6.8 | — | 4.0% | Nov 13, 2007 |
28Monitor | CVE-2010-1440No exploit | Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial tug · tetex · CWE-189 | Medium6.8 | — | 3.4% | May 7, 2010 |
28Monitor | CVE-2007-5937No exploit | Multiple buffer overflows in dvi2xx.c in dviljk in teTeX and TeXlive 2007 and earlier might allow user-assisted attackers to execute arbitratetex · tetex · CWE-119 | Medium6.8 | — | 3.2% | Nov 13, 2007 |
24Monitor | CVE-2015-5700No exploit | mktexlsr revision 22855 through revision 36625 as packaged in texlive allows local users to write to arbitrary files via a symlink attack.tug · texlive · CWE-59 | Medium6.1 | — | 0.4% | Aug 25, 2017 |
24Monitor | CVE-2015-5701No exploit | mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files via a symlink attactug · texlive · CWE-59 | Medium6.1 | — | 0.4% | Aug 25, 2017 |
24Monitor | CVE-2023-46048No exploit | Tex Live 944e257 has a NULL pointer dereference in texk/web2c/pdftexdir/writet1.c.CWE-476 | Medium6.2 | — | 0.3% | Mar 27, 2024 |
22Monitor | CVE-2023-32668No exploit | LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests.luatex project · luatex | Medium5.5 | — | 0.4% | May 11, 2023 |
18Monitor | CVE-2010-0829No exploit | Multiple array index errors in set.c in dvipng 1.11 and 1.12, and teTeX, allow remote attackers to cause a denial of service (application crjan-ake larsson · dvipng · CWE-119 | Medium4.3 | — | 4.5% | May 7, 2010 |
18Monitor | CVE-2007-5940No exploit | feynmf.pl in feynmf 1.08, as used in TeXLive 2007, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink tug · texlive 2007 · CWE-59 | Medium4.6 | — | 0.4% | Nov 13, 2007 |
18Monitor | CVE-2015-0296No exploit | The pre-install script in texlive 3.1.20140525_r34255.fc21 as packaged in Fedora 21 and rpm, and texlive 6.20131226_r32488.fc20 and rpm allotug · texlive · CWE-264 | Medium4.7 | — | 0.4% | Oct 6, 2017 |
14Monitor | CVE-2007-5936No exploit | dvips in teTeX and TeXlive 2007 and earlier allows local users to obtain sensitive information and modify certain data by creating certain ttetex · tetex · CWE-264 | Low3.6 | — | 0.4% | Nov 13, 2007 |
- CVE-2016-1024341Plan
TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf co
CriticalCVSS 9.8No exploitEPSS 7%debian · debian linuxMay 2, 2017
- CVE-2017-1751335Monitor
TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might
HighCVSS 8.8No exploitEPSS 1%tug · tex liveDec 14, 2017
- CVE-2010-264234Monitor
Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possi
HighCVSS 7.6No exploitEPSS 14%t1lib · t1libJan 7, 2011
- CVE-2018-1740732Monitor
An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21.
HighCVSS 7.8No exploitEPSS 2%tug · tex liveSep 23, 2018
- CVE-2024-2526232Monitor
texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump.
HighCVSS 8.1No exploitEPSS 1%Feb 28, 2024
- CVE-2023-3270031Monitor
LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source.
HighCVSS 7.8No exploitEPSS 1%luatex project · luatexMay 20, 2023
- CVE-2010-073928Monitor
Integer overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote attacke
MediumCVSS 6.8No exploitEPSS 5%tug · tetexApr 16, 2010
- CVE-2010-082728Monitor
Integer overflow in dvips in TeX Live 2009 and earlier, and teTeX, allows remote attackers to cause a denial of service (application crash)
MediumCVSS 6.8No exploitEPSS 4%tug · tex liveMay 7, 2010
- CVE-2007-593528Monitor
Stack-based buffer overflow in hpc.c in dvips in teTeX and TeXlive 2007 and earlier allows user-assisted attackers to execute arbitrary code
MediumCVSS 6.8No exploitEPSS 4%tetex · tetexNov 13, 2007
- CVE-2010-144028Monitor
Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial
MediumCVSS 6.8No exploitEPSS 3%tug · tetexMay 7, 2010
- CVE-2007-593728Monitor
Multiple buffer overflows in dvi2xx.c in dviljk in teTeX and TeXlive 2007 and earlier might allow user-assisted attackers to execute arbitra
MediumCVSS 6.8No exploitEPSS 3%tetex · tetexNov 13, 2007
- CVE-2015-570024Monitor
mktexlsr revision 22855 through revision 36625 as packaged in texlive allows local users to write to arbitrary files via a symlink attack.
MediumCVSS 6.1No exploitEPSS 0%tug · texliveAug 25, 2017
- CVE-2015-570124Monitor
mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files via a symlink attac
MediumCVSS 6.1No exploitEPSS 0%tug · texliveAug 25, 2017
- CVE-2023-4604824Monitor
Tex Live 944e257 has a NULL pointer dereference in texk/web2c/pdftexdir/writet1.c.
MediumCVSS 6.2No exploitEPSS 0%Mar 27, 2024
- CVE-2023-3266822Monitor
LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests.
MediumCVSS 5.5No exploitEPSS 0%luatex project · luatexMay 11, 2023
- CVE-2010-082918Monitor
Multiple array index errors in set.c in dvipng 1.11 and 1.12, and teTeX, allow remote attackers to cause a denial of service (application cr
MediumCVSS 4.3No exploitEPSS 5%jan-ake larsson · dvipngMay 7, 2010
- CVE-2007-594018Monitor
feynmf.pl in feynmf 1.08, as used in TeXLive 2007, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink
MediumCVSS 4.6No exploitEPSS 0%tug · texlive 2007Nov 13, 2007
- CVE-2015-029618Monitor
The pre-install script in texlive 3.1.20140525_r34255.fc21 as packaged in Fedora 21 and rpm, and texlive 6.20131226_r32488.fc20 and rpm allo
MediumCVSS 4.7No exploitEPSS 0%tug · texliveOct 6, 2017
- CVE-2007-593614Monitor
dvips in teTeX and TeXlive 2007 and earlier allows local users to obtain sensitive information and modify certain data by creating certain t
LowCVSS 3.6No exploitEPSS 0%tetex · tetexNov 13, 2007