TUG
TUG TEX Live: vulnerabilidades y CVE
TUG TEX Live tiene 10 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses1
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-63729 | Media (6.8) | 0.18% | — | 21 jul 2026 | The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or… |
| CVE-2023-46051 | Baja (3.3) | 0.26% | — | 27 mar 2024 | TeX Live 944e257 allows a NULL pointer dereference in texk/web2c/pdftexdir/tounicode.c. NOTE: this is disputed because it should be categorized as a usability problem. |
| CVE-2023-32700 | Alta (7.8) | 0.80% | — | 20 may 2023 | LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also… |
| CVE-2023-32668 | Media (5.5) | 0.37% | — | 11 may 2023 | LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests. This occurs because full access to the socket library is permitted by default, as stated in the… |
| CVE-2018-17407 | Alta (7.8) | 2.1% | — | 23 sept 2018 | An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the handling of Type 1 fonts allows arbitrary code execution when a malicious font… |
| CVE-2017-17513 | Alta (8.8) | 1.3% | — | 14 dic 2017 | TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL,… |
| CVE-2016-10243 | Crítica (9.8) | 7.1% | — | 2 may 2017 | TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file. |
| CVE-2010-1440 | Media (6.8) | 3.4% | — | 7 may 2010 | Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a special… |
| CVE-2010-0827 | Media (6.8) | 4.4% | — | 7 may 2010 | Integer overflow in dvips in TeX Live 2009 and earlier, and teTeX, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted virtual font (VF) file… |
| CVE-2010-0739 | Media (6.8) | 4.9% | — | 16 abr 2010 | Integer overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote attackers to execute arbitrary code via a crafted DVI file that triggers a heap-based… |