VYPR

Texlive

by TeXLive

CVEs (3)

  • CVE-2023-46048MedMar 27, 2024
    risk 0.40cvss 6.2epss 0.00

    Tex Live 944e257 has a NULL pointer dereference in texk/web2c/pdftexdir/writet1.c. NOTE: this is disputed because it should be categorized as a usability problem.

  • CVE-2015-0296MedOct 6, 2017
    risk 0.31cvss 4.7epss 0.00

    The pre-install script in texlive 3.1.20140525_r34255.fc21 as packaged in Fedora 21 and rpm, and texlive 6.20131226_r32488.fc20 and rpm allows local users to delete arbitrary files via a crafted file in the user's home directory.

  • CVE-2007-5937Nov 13, 2007
    risk 0.00cvss epss 0.03

    Multiple buffer overflows in dvi2xx.c in dviljk in teTeX and TeXlive 2007 and earlier might allow user-assisted attackers to execute arbitrary code via a crafted DVI input file.