VYPR
Vendor

Wiris

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2018-6640CriFeb 28, 2018
    risk 0.64cvss 9.8epss 0.04

    A Heap Overflow (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. Crafted input can modify the next pointer of a linked list. This is fixed in 6.9d.

  • CVE-2018-6638CriFeb 28, 2018
    risk 0.64cvss 9.8epss 0.04

    A stack-based buffer overflow (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. This occurs in a function call in which the first argument is a corrupted offset value and the second argument is a stack buffer. This is fixed in 6.9d.

  • CVE-2022-31372HigJun 16, 2022
    risk 0.00cvss 7.5epss 0.01

    Wiris Mathtype v7.28.0 was discovered to contain a path traversal vulnerability in the resourceFile parameter. This vulnerability is exploited via a crafted request to the resource handler.