VYPR

Ghostscript

by Artifex

Source repositories

CVEs (163)

  • CVE-2017-8291HigKEVApr 27, 2017
    risk 0.73cvss 7.8epss 0.96

    Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs program, as exploited in the wild in April 2017.

  • CVE-2021-3781CriFeb 16, 2022
    risk 0.71cvss 9.9epss 0.84

    A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript…

  • CVE-2019-14813CriSep 6, 2019
    risk 0.65cvss 9.8epss 0.11

    A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then…

  • CVE-2025-27837CriMar 25, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Artifex Ghostscript before 10.05.0. Access to arbitrary files can occur through a truncated path with invalid UTF-8 characters, for base/gp_mswin.c and base/winrtsup.cpp.

  • CVE-2025-27836CriMar 25, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Artifex Ghostscript before 10.05.0. The BJ10V device has a Print buffer overflow in contrib/japanese/gdev10v.c.

  • CVE-2025-27832CriMar 25, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Artifex Ghostscript before 10.05.0. The NPDL device has a Compression buffer overflow for contrib/japanese/gdevnpdl.c.

  • CVE-2025-27831CriMar 25, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Artifex Ghostscript before 10.05.0. The DOCXWRITE TXTWRITE device has a text buffer overflow via long characters to devices/vector/doc_common.c.

  • CVE-2023-28879CriMar 31, 2023
    risk 0.64cvss 9.8epss 0.06

    In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than…

  • CVE-2018-19409CriNov 21, 2018
    risk 0.64cvss 9.8epss 0.08

    An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device is used.

  • CVE-2016-7979CriMay 23, 2017
    risk 0.64cvss 9.8epss 0.06

    Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code by leveraging type confusion in .initialize_dsc_parser.

  • CVE-2016-7978CriMay 23, 2017
    risk 0.64cvss 9.8epss 0.06

    Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors related to a reference leak in .setdevice.

  • CVE-2016-7976HigAug 7, 2017
    risk 0.62cvss 8.8epss 0.23

    The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.

  • CVE-2018-16509HigSep 5, 2018
    risk 0.61cvss 7.8epss 0.93

    An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction.

  • CVE-2018-17961HigOct 15, 2018
    risk 0.60cvss 8.6epss 0.10

    Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue exists because of an incomplete fix for CVE-2018-17183.

  • CVE-2023-43115HigSep 18, 2023
    risk 0.58cvss 8.8epss 0.05

    In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated. NOTE: it is a documented risk that the…

  • CVE-2024-33871HigJul 3, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the Driver parameter for opvp (and oprp) devices can have an…

  • CVE-2024-29509HigJul 3, 2024
    risk 0.57cvss 8.8epss 0.01

    Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle.

  • CVE-2024-29506HigJul 3, 2024
    risk 0.57cvss 8.8epss 0.01

    Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name.

  • CVE-2020-36773CriFeb 4, 2024
    risk 0.57cvss 9.8epss 0.01

    Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).

  • CVE-2019-14869HigNov 15, 2019
    risk 0.57cvss 8.8epss 0.03

    A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted…

Page 1 of 9