Записи tug
19 опубликованных записей вендора tug.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 8
- С записью об исправлении
- 84,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer5
- CWE-59 Improper Link Resolution Before File Access ('Link Following')3
- CWE-189 Numeric Errors3
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-20 Improper Input Validation1
- CWE-476 NULL Pointer Dereference1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
19 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2016-10243Эксплойта нет | TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf codebian · debian linux · CWE-20 | Критическая9,8 | — | 7,1 % | 2 мая 2017 г. |
35Наблюдать | CVE-2017-17513Эксплойта нет | TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might tug · tex live · CWE-74 | Высокая8,8 | — | 1,3 % | 14 дек. 2017 г. |
34Наблюдать | CVE-2010-2642Эксплойта нет | Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possit1lib · t1lib · CWE-119 | Высокая7,6 | — | 14,3 % | 7 янв. 2011 г. |
32Наблюдать | CVE-2018-17407Эксплойта нет | An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21.tug · tex live · CWE-119 | Высокая7,8 | — | 2,1 % | 23 сент. 2018 г. |
32Наблюдать | CVE-2024-25262Эксплойта нет | texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump.CWE-122 | Высокая8,1 | — | 0,9 % | 28 февр. 2024 г. |
31Наблюдать | CVE-2023-32700Эксплойта нет | LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source.luatex project · luatex · CWE-77 | Высокая7,8 | — | 0,8 % | 20 мая 2023 г. |
28Наблюдать | CVE-2010-0739Эксплойта нет | Integer overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote attacketug · tetex · CWE-189 | Средняя6,8 | — | 4,9 % | 16 апр. 2010 г. |
28Наблюдать | CVE-2010-0827Эксплойта нет | Integer overflow in dvips in TeX Live 2009 and earlier, and teTeX, allows remote attackers to cause a denial of service (application crash) tug · tex live · CWE-189 | Средняя6,8 | — | 4,4 % | 7 мая 2010 г. |
28Наблюдать | CVE-2007-5935Эксплойта нет | Stack-based buffer overflow in hpc.c in dvips in teTeX and TeXlive 2007 and earlier allows user-assisted attackers to execute arbitrary codetetex · tetex · CWE-119 | Средняя6,8 | — | 4,0 % | 13 нояб. 2007 г. |
28Наблюдать | CVE-2010-1440Эксплойта нет | Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial tug · tetex · CWE-189 | Средняя6,8 | — | 3,4 % | 7 мая 2010 г. |
28Наблюдать | CVE-2007-5937Эксплойта нет | Multiple buffer overflows in dvi2xx.c in dviljk in teTeX and TeXlive 2007 and earlier might allow user-assisted attackers to execute arbitratetex · tetex · CWE-119 | Средняя6,8 | — | 3,2 % | 13 нояб. 2007 г. |
24Наблюдать | CVE-2015-5700Эксплойта нет | mktexlsr revision 22855 through revision 36625 as packaged in texlive allows local users to write to arbitrary files via a symlink attack.tug · texlive · CWE-59 | Средняя6,1 | — | 0,4 % | 25 авг. 2017 г. |
24Наблюдать | CVE-2015-5701Эксплойта нет | mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files via a symlink attactug · texlive · CWE-59 | Средняя6,1 | — | 0,4 % | 25 авг. 2017 г. |
24Наблюдать | CVE-2023-46048Эксплойта нет | Tex Live 944e257 has a NULL pointer dereference in texk/web2c/pdftexdir/writet1.c.CWE-476 | Средняя6,2 | — | 0,3 % | 27 мар. 2024 г. |
22Наблюдать | CVE-2023-32668Эксплойта нет | LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests.luatex project · luatex | Средняя5,5 | — | 0,4 % | 11 мая 2023 г. |
18Наблюдать | CVE-2010-0829Эксплойта нет | Multiple array index errors in set.c in dvipng 1.11 and 1.12, and teTeX, allow remote attackers to cause a denial of service (application crjan-ake larsson · dvipng · CWE-119 | Средняя4,3 | — | 4,5 % | 7 мая 2010 г. |
18Наблюдать | CVE-2007-5940Эксплойта нет | feynmf.pl in feynmf 1.08, as used in TeXLive 2007, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink tug · texlive 2007 · CWE-59 | Средняя4,6 | — | 0,4 % | 13 нояб. 2007 г. |
18Наблюдать | CVE-2015-0296Эксплойта нет | The pre-install script in texlive 3.1.20140525_r34255.fc21 as packaged in Fedora 21 and rpm, and texlive 6.20131226_r32488.fc20 and rpm allotug · texlive · CWE-264 | Средняя4,7 | — | 0,4 % | 6 окт. 2017 г. |
14Наблюдать | CVE-2007-5936Эксплойта нет | dvips in teTeX and TeXlive 2007 and earlier allows local users to obtain sensitive information and modify certain data by creating certain ttetex · tetex · CWE-264 | Низкая3,6 | — | 0,4 % | 13 нояб. 2007 г. |
- CVE-2016-1024341В плане
TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf co
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %debian · debian linux2 мая 2017 г.
- CVE-2017-1751335Наблюдать
TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %tug · tex live14 дек. 2017 г.
- CVE-2010-264234Наблюдать
Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possi
ВысокаяCVSS 7,6Эксплойта нетEPSS 14 %t1lib · t1lib7 янв. 2011 г.
- CVE-2018-1740732Наблюдать
An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21.
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %tug · tex live23 сент. 2018 г.
- CVE-2024-2526232Наблюдать
texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %28 февр. 2024 г.
- CVE-2023-3270031Наблюдать
LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %luatex project · luatex20 мая 2023 г.
- CVE-2010-073928Наблюдать
Integer overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote attacke
СредняяCVSS 6,8Эксплойта нетEPSS 5 %tug · tetex16 апр. 2010 г.
- CVE-2010-082728Наблюдать
Integer overflow in dvips in TeX Live 2009 and earlier, and teTeX, allows remote attackers to cause a denial of service (application crash)
СредняяCVSS 6,8Эксплойта нетEPSS 4 %tug · tex live7 мая 2010 г.
- CVE-2007-593528Наблюдать
Stack-based buffer overflow in hpc.c in dvips in teTeX and TeXlive 2007 and earlier allows user-assisted attackers to execute arbitrary code
СредняяCVSS 6,8Эксплойта нетEPSS 4 %tetex · tetex13 нояб. 2007 г.
- CVE-2010-144028Наблюдать
Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial
СредняяCVSS 6,8Эксплойта нетEPSS 3 %tug · tetex7 мая 2010 г.
- CVE-2007-593728Наблюдать
Multiple buffer overflows in dvi2xx.c in dviljk in teTeX and TeXlive 2007 and earlier might allow user-assisted attackers to execute arbitra
СредняяCVSS 6,8Эксплойта нетEPSS 3 %tetex · tetex13 нояб. 2007 г.
- CVE-2015-570024Наблюдать
mktexlsr revision 22855 through revision 36625 as packaged in texlive allows local users to write to arbitrary files via a symlink attack.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %tug · texlive25 авг. 2017 г.
- CVE-2015-570124Наблюдать
mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files via a symlink attac
СредняяCVSS 6,1Эксплойта нетEPSS 0 %tug · texlive25 авг. 2017 г.
- CVE-2023-4604824Наблюдать
Tex Live 944e257 has a NULL pointer dereference in texk/web2c/pdftexdir/writet1.c.
СредняяCVSS 6,2Эксплойта нетEPSS 0 %27 мар. 2024 г.
- CVE-2023-3266822Наблюдать
LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %luatex project · luatex11 мая 2023 г.
- CVE-2010-082918Наблюдать
Multiple array index errors in set.c in dvipng 1.11 and 1.12, and teTeX, allow remote attackers to cause a denial of service (application cr
СредняяCVSS 4,3Эксплойта нетEPSS 5 %jan-ake larsson · dvipng7 мая 2010 г.
- CVE-2007-594018Наблюдать
feynmf.pl in feynmf 1.08, as used in TeXLive 2007, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink
СредняяCVSS 4,6Эксплойта нетEPSS 0 %tug · texlive 200713 нояб. 2007 г.
- CVE-2015-029618Наблюдать
The pre-install script in texlive 3.1.20140525_r34255.fc21 as packaged in Fedora 21 and rpm, and texlive 6.20131226_r32488.fc20 and rpm allo
СредняяCVSS 4,7Эксплойта нетEPSS 0 %tug · texlive6 окт. 2017 г.
- CVE-2007-593614Наблюдать
dvips in teTeX and TeXlive 2007 and earlier allows local users to obtain sensitive information and modify certain data by creating certain t
НизкаяCVSS 3,6Эксплойта нетEPSS 0 %tetex · tetex13 нояб. 2007 г.