VYPR
Vendor

Ctan

Products
2
CVEs
8
Across products
8
Status
Private

Products

2

Recent CVEs

8
  • CVE-2024-40446CriApr 22, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted script

  • CVE-2023-51889CriJan 24, 2024
    risk 0.64cvss 9.8epss 0.01

    Stack Overflow vulnerability in the validate() function in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in the application URL.

  • CVE-2023-51887CriJan 24, 2024
    risk 0.64cvss 9.8epss 0.02

    Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in application URL.

  • CVE-2023-51885CriJan 24, 2024
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via the length of the LaTeX string component.

  • CVE-2023-51890HigJan 24, 2024
    risk 0.49cvss 7.5epss 0.01

    An infinite loop issue discovered in Mathtex 1.05 and before allows a remote attackers to consume CPU resources via crafted string in the application URL.

  • CVE-2023-51888HigJan 24, 2024
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability in the nomath() function in Mathtex v.1.05 and before allows a remote attacker to cause a denial of service via a crafted string in the application URL.

  • CVE-2023-51886HigJan 24, 2024
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability in the main() function in Mathtex 1.05 and before allows a remote attacker to cause a denial of service when using \convertpath.

  • CVE-2024-40445HigApr 22, 2025
    risk 0.47cvss 7.3epss 0.01

    A directory traversal vulnerability in forkosh Mime TeX before version 1.77 allows attackers on Windows systems to read or append arbitrary files by manipulating crafted input paths.