Home/Product/tug tex live
Product

tug tex live

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-32700
>= 2017 and < 2023
LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. Thi
7.8HIGH
CVE-2023-32668
>= 2009 and < 2023
LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests. This occurs becaus
5.5MEDIUM
CVE-2018-17407
< 2018-09-21
An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overfl
7.8HIGH
CVE-2017-17513
<= 20170524
TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, wh
8.8HIGH
CVE-2015-0296
all versions
The pre-install script in texlive 3.1.20140525_r34255.fc21 as packaged in Fedora 21 and rpm, and texlive 6.20131226_r32488.fc20 an
4.7MEDIUM
CVE-2015-5701
all versions
mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files via a sym
6.1MEDIUM
CVE-2015-5700
all versions
mktexlsr revision 22855 through revision 36625 as packaged in texlive allows local users to write to arbitrary files via a symlink
6.1MEDIUM
CVE-2016-10243
all versions
TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the te
9.8CRITICAL
CVE-2010-1440
<= 2009
Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause
CVE-2010-0827
<= 2009
Integer overflow in dvips in TeX Live 2009 and earlier, and teTeX, allows remote attackers to cause a denial of service (applicati
CVE-2010-0739
all versions
Integer overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remo
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin