Vulnerabilities > TUG > Texlive 2007 > Medium

DATE CVE VULNERABILITY TITLE RISK
2007-11-13 CVE-2007-5940 Link Following vulnerability in TUG Texlive 2007
feynmf.pl in feynmf 1.08, as used in TeXLive 2007, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on the feynmf$$.pl temporary file.
local
low complexity
tug CWE-59
4.6
2007-11-13 CVE-2007-5937 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Multiple buffer overflows in dvi2xx.c in dviljk in teTeX and TeXlive 2007 and earlier might allow user-assisted attackers to execute arbitrary code via a crafted DVI input file.
network
tetex tug CWE-119
6.8
2007-11-13 CVE-2007-5935 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Stack-based buffer overflow in hpc.c in dvips in teTeX and TeXlive 2007 and earlier allows user-assisted attackers to execute arbitrary code via a DVI file with a long href tag.
network
tetex tug CWE-119
6.8