CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Luatex Project MiktexTug3Luatex MiktexTex LiveJan 31, 2025 May 20, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects...Show more |
3Luatex Project MiktexTug3Luatex MiktexTex LiveNov 3, 2025 May 11, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests. This occurs because full access to the socket library is permitted by default, as stated in the documentatio...Show more |
3Canonical DebianTug3Debian Linux Tex LiveUbuntu LinuxNov 21, 2024 Sep 23, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the handling of Type 1 fonts allows arbitrary code execution when a malicious font i...Show more |
TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL,...Show more |
3Debian FedoraprojectTug3Debian Linux FedoraTex LiveMay 13, 2026 May 2, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file. |
Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a special...Show more |
Integer overflow in dvips in TeX Live 2009 and earlier, and teTeX, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted virtual font (VF) file associat...Show more |
Integer overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote attackers to execute arbitrary code via a crafted DVI file that triggers a heap-based b...Show more |