Skip to content
Noroxi

tug records

19 published records for vendor tug.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
8
With a fix record
84.2%
Median publish → KEV
No record has entered KEV

All records

19 records
  • TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf co

    CriticalCVSS 9.8No exploitEPSS 7%

    debian · debian linuxMay 2, 2017

  • TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might

    HighCVSS 8.8No exploitEPSS 1%

    tug · tex liveDec 14, 2017

  • CVE-2010-2642
    34Monitor

    Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possi

    HighCVSS 7.6No exploitEPSS 14%

    t1lib · t1libJan 7, 2011

  • An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21.

    HighCVSS 7.8No exploitEPSS 2%

    tug · tex liveSep 23, 2018

  • texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump.

    HighCVSS 8.1No exploitEPSS 1%

    Feb 28, 2024

  • LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source.

    HighCVSS 7.8No exploitEPSS 1%

    luatex project · luatexMay 20, 2023

  • CVE-2010-0739
    28Monitor

    Integer overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote attacke

    MediumCVSS 6.8No exploitEPSS 5%

    tug · tetexApr 16, 2010

  • CVE-2010-0827
    28Monitor

    Integer overflow in dvips in TeX Live 2009 and earlier, and teTeX, allows remote attackers to cause a denial of service (application crash)

    MediumCVSS 6.8No exploitEPSS 4%

    tug · tex liveMay 7, 2010

  • CVE-2007-5935
    28Monitor

    Stack-based buffer overflow in hpc.c in dvips in teTeX and TeXlive 2007 and earlier allows user-assisted attackers to execute arbitrary code

    MediumCVSS 6.8No exploitEPSS 4%

    tetex · tetexNov 13, 2007

  • CVE-2010-1440
    28Monitor

    Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial

    MediumCVSS 6.8No exploitEPSS 3%

    tug · tetexMay 7, 2010

  • CVE-2007-5937
    28Monitor

    Multiple buffer overflows in dvi2xx.c in dviljk in teTeX and TeXlive 2007 and earlier might allow user-assisted attackers to execute arbitra

    MediumCVSS 6.8No exploitEPSS 3%

    tetex · tetexNov 13, 2007

  • CVE-2015-5700
    24Monitor

    mktexlsr revision 22855 through revision 36625 as packaged in texlive allows local users to write to arbitrary files via a symlink attack.

    MediumCVSS 6.1No exploitEPSS 0%

    tug · texliveAug 25, 2017

  • CVE-2015-5701
    24Monitor

    mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files via a symlink attac

    MediumCVSS 6.1No exploitEPSS 0%

    tug · texliveAug 25, 2017

  • Tex Live 944e257 has a NULL pointer dereference in texk/web2c/pdftexdir/writet1.c.

    MediumCVSS 6.2No exploitEPSS 0%

    Mar 27, 2024

  • LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests.

    MediumCVSS 5.5No exploitEPSS 0%

    luatex project · luatexMay 11, 2023

  • CVE-2010-0829
    18Monitor

    Multiple array index errors in set.c in dvipng 1.11 and 1.12, and teTeX, allow remote attackers to cause a denial of service (application cr

    MediumCVSS 4.3No exploitEPSS 5%

    jan-ake larsson · dvipngMay 7, 2010

  • CVE-2007-5940
    18Monitor

    feynmf.pl in feynmf 1.08, as used in TeXLive 2007, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink

    MediumCVSS 4.6No exploitEPSS 0%

    tug · texlive 2007Nov 13, 2007

  • CVE-2015-0296
    18Monitor

    The pre-install script in texlive 3.1.20140525_r34255.fc21 as packaged in Fedora 21 and rpm, and texlive 6.20131226_r32488.fc20 and rpm allo

    MediumCVSS 4.7No exploitEPSS 0%

    tug · texliveOct 6, 2017

  • CVE-2007-5936
    14Monitor

    dvips in teTeX and TeXlive 2007 and earlier allows local users to obtain sensitive information and modify certain data by creating certain t

    LowCVSS 3.6No exploitEPSS 0%

    tetex · tetexNov 13, 2007