Tug maintains the TeX Live distribution, a widely used typesetting and document-preparation system embedded in academic, publishing, and technical workflows. The vulnerability profile concentrates on memory-safety and input-handling weaknesses—including buffer boundary violations, symlink-following conditions, and command-injection flaws—that reflect the complexity of parsing and processing untrusted document sources. A meaningful share of disclosed vulnerabilities reach serious severity; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tug over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10243CRITICAL TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file. | May 2, 2017 | 9.8 | 34 | NO | NO |
CVE-2010-2642HIGH Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possibly other products allows remote attacke | Jan 7, 2011 | 7.6 | 31 | NO | NO |
CVE-2018-17407HIGH An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the handling of Type 1 fonts allows arbitrar | Sep 23, 2018 | 7.8 | 26 | NO | NO |
CVE-2023-32700HIGH LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original | May 20, 2023 | 7.8 | 25 | NO | NO |
CVE-2017-17513HIGH TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argume | Dec 14, 2017 | 8.8 | 25 | NO | NO |
CVE-2010-0827MEDIUM Integer overflow in dvips in TeX Live 2009 and earlier, and teTeX, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a | May 7, 2010 | 6.8 | 24 | NO | NO |
CVE-2010-1440MEDIUM Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial of service (application crash) or possib | May 7, 2010 | 6.8 | 23 | NO | NO |
CVE-2010-0739MEDIUM Integer overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote attackers to execute arbitrary code via a craft | Apr 16, 2010 | 6.8 | 23 | NO | NO |
CVE-2023-32668MEDIUM LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests. This occurs because full access to the socket library is permitted b | May 11, 2023 | 5.5 | 20 | NO | NO |
CVE-2015-5701MEDIUM mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files via a symlink attack. NOTE: this vulnerability exists due | Aug 25, 2017 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tug.
Media articles that mention a CVE ID that affects a product developed by Tug — matched by CVE ID, not by vendor name.