tug kayıtları
tug üreticisine ait 19 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 8
- Düzeltme kaydı olan
- %84,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer5
- CWE-59 Improper Link Resolution Before File Access ('Link Following')3
- CWE-189 Numeric Errors3
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-20 Improper Input Validation1
- CWE-476 NULL Pointer Dereference1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
19 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2016-10243İstismar yok | TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf codebian · debian linux · CWE-20 | Kritik9,8 | — | %7,1 | 2 May 2017 |
35İzleyin | CVE-2017-17513İstismar yok | TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might tug · tex live · CWE-74 | Yüksek8,8 | — | %1,3 | 14 Ara 2017 |
34İzleyin | CVE-2010-2642İstismar yok | Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possit1lib · t1lib · CWE-119 | Yüksek7,6 | — | %14,3 | 7 Oca 2011 |
32İzleyin | CVE-2018-17407İstismar yok | An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21.tug · tex live · CWE-119 | Yüksek7,8 | — | %2,1 | 23 Eyl 2018 |
32İzleyin | CVE-2024-25262İstismar yok | texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump.CWE-122 | Yüksek8,1 | — | %0,9 | 28 Şub 2024 |
31İzleyin | CVE-2023-32700İstismar yok | LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source.luatex project · luatex · CWE-77 | Yüksek7,8 | — | %0,8 | 20 May 2023 |
28İzleyin | CVE-2010-0739İstismar yok | Integer overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote attacketug · tetex · CWE-189 | Orta6,8 | — | %4,9 | 16 Nis 2010 |
28İzleyin | CVE-2010-0827İstismar yok | Integer overflow in dvips in TeX Live 2009 and earlier, and teTeX, allows remote attackers to cause a denial of service (application crash) tug · tex live · CWE-189 | Orta6,8 | — | %4,4 | 7 May 2010 |
28İzleyin | CVE-2007-5935İstismar yok | Stack-based buffer overflow in hpc.c in dvips in teTeX and TeXlive 2007 and earlier allows user-assisted attackers to execute arbitrary codetetex · tetex · CWE-119 | Orta6,8 | — | %4,0 | 13 Kas 2007 |
28İzleyin | CVE-2010-1440İstismar yok | Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial tug · tetex · CWE-189 | Orta6,8 | — | %3,4 | 7 May 2010 |
28İzleyin | CVE-2007-5937İstismar yok | Multiple buffer overflows in dvi2xx.c in dviljk in teTeX and TeXlive 2007 and earlier might allow user-assisted attackers to execute arbitratetex · tetex · CWE-119 | Orta6,8 | — | %3,2 | 13 Kas 2007 |
24İzleyin | CVE-2015-5700İstismar yok | mktexlsr revision 22855 through revision 36625 as packaged in texlive allows local users to write to arbitrary files via a symlink attack.tug · texlive · CWE-59 | Orta6,1 | — | %0,4 | 25 Ağu 2017 |
24İzleyin | CVE-2015-5701İstismar yok | mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files via a symlink attactug · texlive · CWE-59 | Orta6,1 | — | %0,4 | 25 Ağu 2017 |
24İzleyin | CVE-2023-46048İstismar yok | Tex Live 944e257 has a NULL pointer dereference in texk/web2c/pdftexdir/writet1.c.CWE-476 | Orta6,2 | — | %0,3 | 27 Mar 2024 |
22İzleyin | CVE-2023-32668İstismar yok | LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests.luatex project · luatex | Orta5,5 | — | %0,4 | 11 May 2023 |
18İzleyin | CVE-2010-0829İstismar yok | Multiple array index errors in set.c in dvipng 1.11 and 1.12, and teTeX, allow remote attackers to cause a denial of service (application crjan-ake larsson · dvipng · CWE-119 | Orta4,3 | — | %4,5 | 7 May 2010 |
18İzleyin | CVE-2007-5940İstismar yok | feynmf.pl in feynmf 1.08, as used in TeXLive 2007, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink tug · texlive 2007 · CWE-59 | Orta4,6 | — | %0,4 | 13 Kas 2007 |
18İzleyin | CVE-2015-0296İstismar yok | The pre-install script in texlive 3.1.20140525_r34255.fc21 as packaged in Fedora 21 and rpm, and texlive 6.20131226_r32488.fc20 and rpm allotug · texlive · CWE-264 | Orta4,7 | — | %0,4 | 6 Eki 2017 |
14İzleyin | CVE-2007-5936İstismar yok | dvips in teTeX and TeXlive 2007 and earlier allows local users to obtain sensitive information and modify certain data by creating certain ttetex · tetex · CWE-264 | Düşük3,6 | — | %0,4 | 13 Kas 2007 |
- CVE-2016-1024341Planlayın
TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf co
KritikCVSS 9,8İstismar yokEPSS %7debian · debian linux2 May 2017
- CVE-2017-1751335İzleyin
TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might
YüksekCVSS 8,8İstismar yokEPSS %1tug · tex live14 Ara 2017
- CVE-2010-264234İzleyin
Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possi
YüksekCVSS 7,6İstismar yokEPSS %14t1lib · t1lib7 Oca 2011
- CVE-2018-1740732İzleyin
An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21.
YüksekCVSS 7,8İstismar yokEPSS %2tug · tex live23 Eyl 2018
- CVE-2024-2526232İzleyin
texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump.
YüksekCVSS 8,1İstismar yokEPSS %128 Şub 2024
- CVE-2023-3270031İzleyin
LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source.
YüksekCVSS 7,8İstismar yokEPSS %1luatex project · luatex20 May 2023
- CVE-2010-073928İzleyin
Integer overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote attacke
OrtaCVSS 6,8İstismar yokEPSS %5tug · tetex16 Nis 2010
- CVE-2010-082728İzleyin
Integer overflow in dvips in TeX Live 2009 and earlier, and teTeX, allows remote attackers to cause a denial of service (application crash)
OrtaCVSS 6,8İstismar yokEPSS %4tug · tex live7 May 2010
- CVE-2007-593528İzleyin
Stack-based buffer overflow in hpc.c in dvips in teTeX and TeXlive 2007 and earlier allows user-assisted attackers to execute arbitrary code
OrtaCVSS 6,8İstismar yokEPSS %4tetex · tetex13 Kas 2007
- CVE-2010-144028İzleyin
Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial
OrtaCVSS 6,8İstismar yokEPSS %3tug · tetex7 May 2010
- CVE-2007-593728İzleyin
Multiple buffer overflows in dvi2xx.c in dviljk in teTeX and TeXlive 2007 and earlier might allow user-assisted attackers to execute arbitra
OrtaCVSS 6,8İstismar yokEPSS %3tetex · tetex13 Kas 2007
- CVE-2015-570024İzleyin
mktexlsr revision 22855 through revision 36625 as packaged in texlive allows local users to write to arbitrary files via a symlink attack.
OrtaCVSS 6,1İstismar yokEPSS %0tug · texlive25 Ağu 2017
- CVE-2015-570124İzleyin
mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files via a symlink attac
OrtaCVSS 6,1İstismar yokEPSS %0tug · texlive25 Ağu 2017
- CVE-2023-4604824İzleyin
Tex Live 944e257 has a NULL pointer dereference in texk/web2c/pdftexdir/writet1.c.
OrtaCVSS 6,2İstismar yokEPSS %027 Mar 2024
- CVE-2023-3266822İzleyin
LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests.
OrtaCVSS 5,5İstismar yokEPSS %0luatex project · luatex11 May 2023
- CVE-2010-082918İzleyin
Multiple array index errors in set.c in dvipng 1.11 and 1.12, and teTeX, allow remote attackers to cause a denial of service (application cr
OrtaCVSS 4,3İstismar yokEPSS %5jan-ake larsson · dvipng7 May 2010
- CVE-2007-594018İzleyin
feynmf.pl in feynmf 1.08, as used in TeXLive 2007, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink
OrtaCVSS 4,6İstismar yokEPSS %0tug · texlive 200713 Kas 2007
- CVE-2015-029618İzleyin
The pre-install script in texlive 3.1.20140525_r34255.fc21 as packaged in Fedora 21 and rpm, and texlive 6.20131226_r32488.fc20 and rpm allo
OrtaCVSS 4,7İstismar yokEPSS %0tug · texlive6 Eki 2017
- CVE-2007-593614İzleyin
dvips in teTeX and TeXlive 2007 and earlier allows local users to obtain sensitive information and modify certain data by creating certain t
DüşükCVSS 3,6İstismar yokEPSS %0tetex · tetex13 Kas 2007