Wiris maintains MathType, a specialized mathematical typesetting and equation-editing tool widely embedded in educational platforms and document-authoring systems, where its vulnerabilities have centered on memory-safety issues such as out-of-bounds writes and use-after-free conditions alongside path-traversal flaws in file handling. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wiris over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-6641CRITICAL An Arbitrary Free (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. Crafted input can overwrite a structure, leading to a function call with an invalid | Feb 28, 2018 | 9.8 | 33 | NO | NO |
CVE-2018-6639CRITICAL An out-of-bounds write (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. A size used by memmove is read from the input file. This is fixed in 6.9d. | Feb 28, 2018 | 9.8 | 32 | NO | NO |
CVE-2018-6640CRITICAL A Heap Overflow (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. Crafted input can modify the next pointer of a linked list. This is fixed in 6.9d. | Feb 28, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-6638CRITICAL A stack-based buffer overflow (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. This occurs in a function call in which the first argument is a corrupte | Feb 28, 2018 | 9.8 | 30 | NO | NO |
CVE-2022-31372HIGH Wiris Mathtype v7.28.0 was discovered to contain a path traversal vulnerability in the resourceFile parameter. This vulnerability is exploited via a crafted request to the resource | Jun 16, 2022 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wiris.
Media articles that mention a CVE ID that affects a product developed by Wiris — matched by CVE ID, not by vendor name.