Перейти к содержимому
Noroxi

Записи tug

19 опубликованных записей вендора tug.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
8
С записью об исправлении
84,2 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

  1. 17
  2. 18
  3. 23
  4. 24

Столбик: всего · тёмная часть: CISA KEV.

Все записи

19 записей
  • CVE-2016-10243
    41В плане

    TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf co

    КритическаяCVSS 9,8Эксплойта нетEPSS 7 %

    debian · debian linux2 мая 2017 г.

  • CVE-2017-17513
    35Наблюдать

    TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    tug · tex live14 дек. 2017 г.

  • CVE-2010-2642
    34Наблюдать

    Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possi

    ВысокаяCVSS 7,6Эксплойта нетEPSS 14 %

    t1lib · t1lib7 янв. 2011 г.

  • CVE-2018-17407
    32Наблюдать

    An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %

    tug · tex live23 сент. 2018 г.

  • CVE-2024-25262
    32Наблюдать

    texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump.

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    28 февр. 2024 г.

  • CVE-2023-32700
    31Наблюдать

    LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    luatex project · luatex20 мая 2023 г.

  • CVE-2010-0739
    28Наблюдать

    Integer overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote attacke

    СредняяCVSS 6,8Эксплойта нетEPSS 5 %

    tug · tetex16 апр. 2010 г.

  • CVE-2010-0827
    28Наблюдать

    Integer overflow in dvips in TeX Live 2009 and earlier, and teTeX, allows remote attackers to cause a denial of service (application crash)

    СредняяCVSS 6,8Эксплойта нетEPSS 4 %

    tug · tex live7 мая 2010 г.

  • CVE-2007-5935
    28Наблюдать

    Stack-based buffer overflow in hpc.c in dvips in teTeX and TeXlive 2007 and earlier allows user-assisted attackers to execute arbitrary code

    СредняяCVSS 6,8Эксплойта нетEPSS 4 %

    tetex · tetex13 нояб. 2007 г.

  • CVE-2010-1440
    28Наблюдать

    Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial

    СредняяCVSS 6,8Эксплойта нетEPSS 3 %

    tug · tetex7 мая 2010 г.

  • CVE-2007-5937
    28Наблюдать

    Multiple buffer overflows in dvi2xx.c in dviljk in teTeX and TeXlive 2007 and earlier might allow user-assisted attackers to execute arbitra

    СредняяCVSS 6,8Эксплойта нетEPSS 3 %

    tetex · tetex13 нояб. 2007 г.

  • CVE-2015-5700
    24Наблюдать

    mktexlsr revision 22855 through revision 36625 as packaged in texlive allows local users to write to arbitrary files via a symlink attack.

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    tug · texlive25 авг. 2017 г.

  • CVE-2015-5701
    24Наблюдать

    mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files via a symlink attac

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    tug · texlive25 авг. 2017 г.

  • CVE-2023-46048
    24Наблюдать

    Tex Live 944e257 has a NULL pointer dereference in texk/web2c/pdftexdir/writet1.c.

    СредняяCVSS 6,2Эксплойта нетEPSS 0 %

    27 мар. 2024 г.

  • CVE-2023-32668
    22Наблюдать

    LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests.

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    luatex project · luatex11 мая 2023 г.

  • CVE-2010-0829
    18Наблюдать

    Multiple array index errors in set.c in dvipng 1.11 and 1.12, and teTeX, allow remote attackers to cause a denial of service (application cr

    СредняяCVSS 4,3Эксплойта нетEPSS 5 %

    jan-ake larsson · dvipng7 мая 2010 г.

  • CVE-2007-5940
    18Наблюдать

    feynmf.pl in feynmf 1.08, as used in TeXLive 2007, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink

    СредняяCVSS 4,6Эксплойта нетEPSS 0 %

    tug · texlive 200713 нояб. 2007 г.

  • CVE-2015-0296
    18Наблюдать

    The pre-install script in texlive 3.1.20140525_r34255.fc21 as packaged in Fedora 21 and rpm, and texlive 6.20131226_r32488.fc20 and rpm allo

    СредняяCVSS 4,7Эксплойта нетEPSS 0 %

    tug · texlive6 окт. 2017 г.

  • CVE-2007-5936
    14Наблюдать

    dvips in teTeX and TeXlive 2007 and earlier allows local users to obtain sensitive information and modify certain data by creating certain t

    НизкаяCVSS 3,6Эксплойта нетEPSS 0 %

    tetex · tetex13 нояб. 2007 г.