Tetex is a document processing and typesetting system that, while maintaining a narrow product scope, holds prominence in academic and technical publishing workflows where its output quality is relied upon. The system's vulnerability profile centers on memory-safety and bounds-checking weaknesses characteristic of software handling complex document parsing and rendering, with a moderate tendency toward public exploit availability. Defenders should monitor this vendor's releases for systems processing untrusted documents; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tetex over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0888HIGH Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (cras | Jan 27, 2005 | 10.0 | 34 | NO | NO |
CVE-2004-0889HIGH Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitra | Jan 27, 2005 | 10.0 | 33 | NO | NO |
CVE-2009-3608HIGH Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and te | Oct 21, 2009 | 9.3 | 32 | NO | NO |
CVE-2001-0906MEDIUM teTeX filter before 1.0.7 allows local users to gain privileges via a symlink attack on temporary files that are produced when printing .dvi files using lpr. | Jun 22, 2001 | 6.2 | 30 | NO | YES |
CVE-2005-3625HIGH Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams t | Dec 31, 2005 | 10.0 | 26 | NO | NO |
CVE-2011-0433MEDIUM Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allows remote attackers to cause a d | Nov 19, 2012 | 6.8 | 24 | NO | NO |
CVE-2011-5244MEDIUM Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other produc | Nov 19, 2012 | 6.8 | 23 | NO | NO |
CVE-2005-0206HIGH The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which coul | Apr 27, 2005 | 7.5 | 20 | NO | NO |
CVE-2007-5935MEDIUM Stack-based buffer overflow in hpc.c in dvips in teTeX and TeXlive 2007 and earlier allows user-assisted attackers to execute arbitrary code via a DVI file with a long href tag. | Nov 13, 2007 | 6.8 | 19 | NO | NO |
CVE-2007-5937MEDIUM Multiple buffer overflows in dvi2xx.c in dviljk in teTeX and TeXlive 2007 and earlier might allow user-assisted attackers to execute arbitrary code via a crafted DVI input file. | Nov 13, 2007 | 6.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tetex.
Media articles that mention a CVE ID that affects a product developed by Tetex — matched by CVE ID, not by vendor name.