6.8

CVE-2010-1440

Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a special command in a DVI file, related to the (1) predospecial and (2) bbdospecial functions, a different vulnerability than CVE-2010-0739.

Data is provided by the National Vulnerability Database (NVD)
TugTetex
TugTex Live Version <= 2009
TugTex Live Version1996
TugTex Live Version1998
TugTex Live Version1999
TugTex Live Version2000
TugTex Live Version2001
TugTex Live Version2002
TugTex Live Version2003
TugTex Live Version2004
TugTex Live Version2005
TugTex Live Version2007
TugTex Live Version2008
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.85% 0.849
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P