Latex2rtf Project develops a document-conversion utility that translates LaTeX markup into Rich Text Format, a modestly used tool in academic and technical publishing workflows. The observed vulnerability pattern centers on format-string handling in input processing, a classic weakness class in text-parsing utilities that warrants careful review during deployment and updates. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Latex2rtf Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-2167HIGH Multiple buffer overflows in LaTeX2rtf 1.9.15, and possibly other versions, allow remote attackers to execute arbitrary code via (1) the expandmacro function, and possibly (2) Envi | Dec 31, 2004 | 7.5 | 35 | NO | YES |
CVE-2015-8106HIGH Format string vulnerability in the CmdKeywords function in funct1.c in latex2rtf before 2.3.10 allows remote attackers to execute arbitrary code via format string specifiers in the | Apr 18, 2016 | 7.8 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Latex2rtf Project.
Media articles that mention a CVE ID that affects a product developed by Latex2rtf Project — matched by CVE ID, not by vendor name.