Texlive

Vendor:

First CVE: Apr 16, 2010 · Active for 16 years

11
Total CVEs
More Total CVEs than 64% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Texlive over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 16, 2010
16 years ago
Most Recent CVE
May 20, 2023
1,162 days ago

CVE Severity & Scoring

Texlive11 CVEs
All CVEs352,427 CVEs
MediumHighCritical
Attack Vector
Local6 (54.5%)
Network2 (18.2%)
Unknown3 (27.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (63.6%)
High1 (9.1%)
Unknown3 (27.3%)
User Interaction
None3 (27.3%)
Unknown3 (27.3%)
Required5 (45.5%)
Privileges Required
Low2 (18.2%)
High0 (0.0%)
None6 (54.5%)
Unknown3 (27.3%)

Top CVEs

Signals from CVEs in this product scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.
May 2, 20179.834NONO
An issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the handling of Type 1 fonts allows arbitrar
Sep 23, 20187.826NONO
LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original
May 20, 20237.825NONO
TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argume
Dec 14, 20178.825NONO
Integer overflow in dvips in TeX Live 2009 and earlier, and teTeX, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a
May 7, 20106.824NONO
Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial of service (application crash) or possib
May 7, 20106.823NONO
Integer overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote attackers to execute arbitrary code via a craft
Apr 16, 20106.823NONO
LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests. This occurs because full access to the socket library is permitted b
May 11, 20235.520NONO
mktexlsr revision 36855, and before revision 36626 as packaged in texlive allows local users to write to arbitrary files via a symlink attack. NOTE: this vulnerability exists due
Aug 25, 20176.120NONO
mktexlsr revision 22855 through revision 36625 as packaged in texlive allows local users to write to arbitrary files via a symlink attack.
Aug 25, 20176.120NONO

Exploit Exposure

Signals from CVEs in this product scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (11 CVEs).

Media Mentions

Signals from CVEs in this product scope (11 CVEs).

Top CNAs Publishing CVEs For Texlive

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.20131226_r32488.fc2014.70.4%00
3.1.20140525_r34255.fc2114.70.4%00
2014052526.10.4%00
2013053026.10.4%00
2012070126.10.4%00
2011070526.10.4%00
2010072226.10.4%00
200826.83.9%00
200726.83.9%00
200526.83.9%00
200426.83.9%00
200326.83.9%00
200226.83.9%00
200126.83.9%00
200026.83.9%00
199926.83.9%00
199826.83.9%00
199626.83.9%00