Tcl Tk is a scripting language and GUI toolkit that, despite a narrow product footprint, maintains a durable presence in embedded systems, system administration tools, and cross-platform applications where interpreted scripting meets graphical needs. The recurring vulnerability exposure centers on memory-safety issues, particularly improper restriction of operations within memory buffer bounds, reflecting the demands of implementing an interpreter and UI framework in lower-level languages. Current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tcl Tk over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-5137MEDIUM Buffer overflow in the ReadImage function in generic/tkImgGIF.c in Tcl (Tcl/Tk) 8.4.13 through 8.4.15 allows remote attackers to execute arbitrary code via multi-frame interlaced G | Sep 28, 2007 | 6.8 | 22 | NO | NO |
CVE-2007-4769MEDIUM The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated | Jan 9, 2008 | 6.8 | 21 | NO | NO |
CVE-2008-0553MEDIUM Stack-based buffer overflow in the ReadImage function in tkImgGIF.c in Tk (Tcl/Tk) before 8.5.1 allows remote attackers to execute arbitrary code via a crafted GIF image, a similar | Feb 7, 2008 | 6.8 | 20 | NO | NO |
CVE-2007-6067MEDIUM Algorithmic complexity vulnerability in the regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 be | Jan 9, 2008 | 6.8 | 20 | NO | NO |
CVE-2007-2877HIGH Buffer overflow in tcl/win/tclWinReg.c in Tcl (Tcl/Tk) before 8.5a6 allows local users to gain privileges via long registry key paths. | May 29, 2007 | 7.2 | 18 | NO | NO |
CVE-2007-5378MEDIUM Buffer overflow in the FileReadGIF function in tkImgGIF.c for Tk Toolkit 8.4.12 and earlier, and 8.3.5 and earlier, allows user-assisted attackers to cause a denial of service (seg | Oct 12, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tcl Tk.
Media articles that mention a CVE ID that affects a product developed by Tcl Tk — matched by CVE ID, not by vendor name.