peter bassill · operator
$ cve CVE-2018-6641 JSON

CVE-2018-6641

9.8
CRITICAL · CVSS 3.1 · EPSS 5.6% (pctl 93)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An Arbitrary Free (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. Crafted input can overwrite a structure, leading to a function call with an invalid parameter, and a subsequent free of important data such as a function pointer or list pointer. This is fixed in 6.9d.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.55% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-416
On CISA KEVno
Public exploitnone known
Published2018-02-28
Last modified2026-06-17

Affected (1)

VendorProduct
wirismathtype

References

→ the Explorer  ·  watch your stack  ·  NVD