[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256148

 
 

909

 
 

199106

 
 

282

Paid content will be excluded from the download.


Download | Alert*


CVE-2023-32668
LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests. This occurs because full access to the socket library is permitted by default, as stated in the documentation. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.

CVE-2024-25262
texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted TTF file.

*OVAL
oval:org.secpod.oval:def:98772
CPE    8
cpe:/a:tug:texlive-binaries
cpe:/a:libtexluajit2:libtexluajit2
cpe:/a:libtexluajit-dev:libtexluajit-dev
cpe:/a:libptexenc1:libptexenc1
...

© SecPod Technologies