Texlive
Vendor:
First CVE: Apr 16, 2010 · Active for 16 years
11
Total CVEs
More Total CVEs than 64% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Texlive over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 16, 2010
16 years ago
Most Recent CVE
May 20, 2023
1,162 days ago
CVE Severity & Scoring
Texlive11 CVEs
64%
27%
9%
All CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local6 (54.5%)
Network2 (18.2%)
Unknown3 (27.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (63.6%)
High1 (9.1%)
Unknown3 (27.3%)
User Interaction
None3 (27.3%)
Unknown3 (27.3%)
Required5 (45.5%)
Privileges Required
Low2 (18.2%)
High0 (0.0%)
None6 (54.5%)
Unknown3 (27.3%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10243CRITICAL TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file. | May 2, 2017 | 9.8 | 34 | NO | NO |
CVE-2018-17407HIGH An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the handling of Type 1 fonts allows arbitrar | Sep 23, 2018 | 7.8 | 26 | NO | NO |
CVE-2023-32700HIGH LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original | May 20, 2023 | 7.8 | 25 | NO | NO |
CVE-2017-17513HIGH TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argume | Dec 14, 2017 | 8.8 | 25 | NO | NO |
CVE-2010-0827MEDIUM Integer overflow in dvips in TeX Live 2009 and earlier, and teTeX, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a | May 7, 2010 | 6.8 | 24 | NO | NO |
CVE-2010-1440MEDIUM Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial of service (application crash) or possib | May 7, 2010 | 6.8 | 23 | NO | NO |
CVE-2010-0739MEDIUM Integer overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote attackers to execute arbitrary code via a craft | Apr 16, 2010 | 6.8 | 23 | NO | NO |
CVE-2023-32668MEDIUM LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests. This occurs because full access to the socket library is permitted b | May 11, 2023 | 5.5 | 20 | NO | NO |
CVE-2015-5701MEDIUM mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files via a symlink attack. NOTE: this vulnerability exists due | Aug 25, 2017 | 6.1 | 20 | NO | NO |
CVE-2015-5700MEDIUM mktexlsr revision 22855 through revision 36625 as packaged in texlive allows local users to write to arbitrary files via a symlink attack. | Aug 25, 2017 | 6.1 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Texlive
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.20131226_r32488.fc20 | 1 | 4.7 | 0.4% | 0 | 0 |
| 3.1.20140525_r34255.fc21 | 1 | 4.7 | 0.4% | 0 | 0 |
| 20140525 | 2 | 6.1 | 0.4% | 0 | 0 |
| 20130530 | 2 | 6.1 | 0.4% | 0 | 0 |
| 20120701 | 2 | 6.1 | 0.4% | 0 | 0 |
| 20110705 | 2 | 6.1 | 0.4% | 0 | 0 |
| 20100722 | 2 | 6.1 | 0.4% | 0 | 0 |
| 2008 | 2 | 6.8 | 3.9% | 0 | 0 |
| 2007 | 2 | 6.8 | 3.9% | 0 | 0 |
| 2005 | 2 | 6.8 | 3.9% | 0 | 0 |
| 2004 | 2 | 6.8 | 3.9% | 0 | 0 |
| 2003 | 2 | 6.8 | 3.9% | 0 | 0 |
| 2002 | 2 | 6.8 | 3.9% | 0 | 0 |
| 2001 | 2 | 6.8 | 3.9% | 0 | 0 |
| 2000 | 2 | 6.8 | 3.9% | 0 | 0 |
| 1999 | 2 | 6.8 | 3.9% | 0 | 0 |
| 1998 | 2 | 6.8 | 3.9% | 0 | 0 |
| 1996 | 2 | 6.8 | 3.9% | 0 | 0 |