VYPR

Mathtex

by Ctan

CVEs (6)

  • CVE-2023-51889CriJan 24, 2024
    risk 0.64cvss 9.8epss 0.01

    Stack Overflow vulnerability in the validate() function in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in the application URL.

  • CVE-2023-51887CriJan 24, 2024
    risk 0.64cvss 9.8epss 0.02

    Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in application URL.

  • CVE-2023-51885CriJan 24, 2024
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via the length of the LaTeX string component.

  • CVE-2023-51890HigJan 24, 2024
    risk 0.49cvss 7.5epss 0.01

    An infinite loop issue discovered in Mathtex 1.05 and before allows a remote attackers to consume CPU resources via crafted string in the application URL.

  • CVE-2023-51888HigJan 24, 2024
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability in the nomath() function in Mathtex v.1.05 and before allows a remote attacker to cause a denial of service via a crafted string in the application URL.

  • CVE-2023-51886HigJan 24, 2024
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability in the main() function in Mathtex 1.05 and before allows a remote attacker to cause a denial of service when using \convertpath.