CVE-2010-0829 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Dvipng
Severity
4.3MEDIUMNVD
EPSS
5.0%
top 10.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 7
Latest updateMay 2
Description
Multiple array index errors in set.c in dvipng 1.11 and 1.12, and teTeX, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed DVI file.
CVSS vector
AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9