Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-40445_CVE-2024-40446 — This repository serves as the public reference for CVE-2024-40445 and CVE-2024-40446. Both vulnerabilities impact MimeTeX, an open-source software package for rendering LaTeX expressions, which appears to be no longer maintained. | Kitploit
Tools/GitHubGitHub/taiyou-tw/cve-2024-40445_cve-2024-40446
Vulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationPapers & ResearchLearning & Education
GitHubtaiyou-tw/cve-2024-40445_cve-2024-40446

CVE-2024-40445_CVE-2024-40446

This repository serves as the public reference for CVE-2024-40445 and CVE-2024-40446. Both vulnerabilities impact MimeTeX, an open-source software package for rendering LaTeX expressions, which appears to be no longer maintained.

View Repository
461 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

MimeTeX Vulnerability Reference (CVE-2024-40445 & CVE-2024-40446)

This repository serves as the public reference for the security issues CVE-2024-40445 and CVE-2024-40446 affecting MimeTeX, a lightweight open-source LaTeX renderer written in C.

⚠️ MimeTeX appears to be no longer actively maintained. Users and developers are strongly encouraged to assess the risks before using it in production environments.

Vulnerabilities

CVE-2024-40445 — Directory Traversal

A directory traversal vulnerability exists in MimeTeX prior to version 1.77. When operating in command-line or CGI mode, crafted user input can be used to perform unauthorized file access operations on Windows System.

CVE-2024-40446 — Code Injection

MimeTeX versions from 1.76 up to 1.77 contain a code injection vulnerability. A malicious input string, when parsed by the engine, can trigger unintended command execution.

Possibly Affected Users

If you are a user of Moodle, which appears to be one of the main platforms still using MimeTeX, please refer to their advisory for mitigation guidance.

Mitigation

If you are using MimeTeX:

  • Stop using it, as it appears to be unmaintained and vulnerable.
  • Restrict user input if usage cannot be immediately discontinued.
  • Isolate the service using sandboxing or containerization to limit the impact of potential exploits.

Disclaimer

This repository is for informational purposes only. Technical details have been redacted to minimize potential risks to users and systems still using affected versions.


CVE IDs: CVE-2024-40445, CVE-2024-40446
Vendor: forkosh
Status: Affected versions are no longer actively maintained.

Download Tool