Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ctan

First CVE: Jan 24, 2024Active for: 2 yearsTotal CVEs: 8

Ctan maintains a small portfolio of mathematical typesetting and rendering tools, including MathTeX and MimeTeX, that process untrusted mathematical markup input from web applications and documents. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through dangerous input-handling weakness classes—buffer overflows, command injection, code injection, infinite loops, and out-of-bounds writes—that reflect the parsing complexity inherent to converting mathematical notation into rendered output. Defenders deploying these tools should treat input sanitization as essential and monitor for patches addressing parsing and code-generation flaws; live severity and exploitation details are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
8.6
Avg CVSS Score
Higher Avg CVSS Score than 83% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ctan over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 24, 2024
2 years ago
Most Recent CVE
Apr 22, 2025
458 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-40446CRITICAL
An issue in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted script
Apr 22, 20259.830NONO
CVE-2023-51889CRITICAL
Stack Overflow vulnerability in the validate() function in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in the application URL.
Jan 24, 20249.830NONO
CVE-2023-51887CRITICAL
Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in application URL.
Jan 24, 20249.827NONO
CVE-2023-51885CRITICAL
Buffer Overflow vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via the length of the LaTeX string component.
Jan 24, 20249.824NONO
CVE-2023-51890HIGH
An infinite loop issue discovered in Mathtex 1.05 and before allows a remote attackers to consume CPU resources via crafted string in the application URL.
Jan 24, 20247.522NONO
CVE-2023-51888HIGH
Buffer Overflow vulnerability in the nomath() function in Mathtex v.1.05 and before allows a remote attacker to cause a denial of service via a crafted string in the application UR
Jan 24, 20247.522NONO
CVE-2023-51886HIGH
Buffer Overflow vulnerability in the main() function in Mathtex 1.05 and before allows a remote attacker to cause a denial of service when using \convertpath.
Jan 24, 20247.522NONO
CVE-2024-40445HIGH
A directory traversal vulnerability in forkosh Mime TeX before version 1.77 allows attackers on Windows systems to read or append arbitrary files by manipulating crafted input path
Apr 22, 20257.321NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
50%
50%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None8 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ctan.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ctan — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ctan's Products

View all 1 CNAs →

Top CWEs