VYPR

Ghostscript

by Artifex

Source repositories

CVEs (163)

  • CVE-2019-6116HigMar 21, 2019
    risk 0.57cvss 7.8epss 0.39

    In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.

  • CVE-2018-18284HigOct 19, 2018
    risk 0.57cvss 8.6epss 0.16

    Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator.

  • CVE-2025-27835HigMar 25, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs when converting glyphs to Unicode in psi/zbfont.c.

  • CVE-2025-27834HigMar 25, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs via an oversized Type 4 function in a PDF document to pdf/pdf_func.c.

  • CVE-2025-27833HigMar 25, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs for a long TTF font name to pdf/pdf_fmap.c.

  • CVE-2025-27830HigMar 25, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs during serialization of DollarBlend in a font, for base/write_t1.c and psi/zfapi.c.

  • CVE-2024-46956HigNov 10, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.

  • CVE-2024-46954HigNov 10, 2024
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.

  • CVE-2024-46953HigNov 10, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.

  • CVE-2024-46952HigNov 10, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in pdf/pdf_xref.c in Artifex Ghostscript before 10.04.0. There is a buffer overflow during handling of a PDF XRef stream (related to W array values).

  • CVE-2024-46951HigNov 10, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.

  • CVE-2020-21890HigAug 22, 2023
    risk 0.51cvss 7.8epss 0.01

    Buffer Overflow vulnerability in clj_media_size function in devices/gdevclj.c in Artifex Ghostscript 9.50 allows remote attackers to cause a denial of service or other unspecified impact(s) via opening of crafted PDF document.

  • CVE-2023-36664HigJun 25, 2023
    risk 0.51cvss 7.8epss 0.03

    Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).

  • CVE-2019-25059HigApr 25, 2022
    risk 0.51cvss 7.8epss 0.01

    Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.

  • CVE-2020-16303HigAug 13, 2020
    risk 0.51cvss 7.8epss 0.02

    A use-after-free vulnerability in xps_finish_image_path() in devices/vector/gdevxps.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51.

  • CVE-2019-14812HigNov 27, 2019
    risk 0.51cvss 7.8epss 0.02

    A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then…

  • CVE-2019-10216HigNov 27, 2019
    risk 0.51cvss 7.8epss 0.02

    In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and…

  • CVE-2019-14817HigSep 3, 2019
    risk 0.51cvss 7.8epss 0.02

    A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and…

  • CVE-2019-14811HigSep 3, 2019
    risk 0.51cvss 7.8epss 0.04

    A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and…

  • CVE-2018-19134HigDec 20, 2018
    risk 0.51cvss 7.8epss 0.03

    In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscript process. This is a type…

Page 2 of 9