VYPR

Ghostscript

by Artifex

Source repositories

CVEs (160)

  • CVE-2009-0196Apr 16, 2009
    risk 0.01cvss epss 0.07

    Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute arbitrary code via a PDF file with a JBIG2 symbol dictionary…

  • CVE-2025-59800Sep 22, 2025
    risk 0.00cvss epss 0.00

    In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8.

  • CVE-2025-59798Sep 22, 2025
    risk 0.00cvss epss 0.00

    Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c.

  • CVE-2025-59799Sep 22, 2025
    risk 0.00cvss epss 0.00

    Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdfmark_coerce_dest in devices/vector/gdevpdfm.c via a large size value.

  • CVE-2025-48708May 23, 2025
    risk 0.00cvss epss 0.00

    gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.

  • CVE-2025-46646Apr 26, 2025
    risk 0.00cvss epss 0.00

    In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954.

  • CVE-2025-27837Mar 25, 2025
    risk 0.00cvss epss 0.01

    An issue was discovered in Artifex Ghostscript before 10.05.0. Access to arbitrary files can occur through a truncated path with invalid UTF-8 characters, for base/gp_mswin.c and base/winrtsup.cpp.

  • CVE-2025-27836Mar 25, 2025
    risk 0.00cvss epss 0.01

    An issue was discovered in Artifex Ghostscript before 10.05.0. The BJ10V device has a Print buffer overflow in contrib/japanese/gdev10v.c.

  • CVE-2025-27831Mar 25, 2025
    risk 0.00cvss epss 0.01

    An issue was discovered in Artifex Ghostscript before 10.05.0. The DOCXWRITE TXTWRITE device has a text buffer overflow via long characters to devices/vector/doc_common.c.

  • CVE-2025-27833Mar 25, 2025
    risk 0.00cvss epss 0.00

    An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs for a long TTF font name to pdf/pdf_fmap.c.

  • CVE-2025-27830Mar 25, 2025
    risk 0.00cvss epss 0.00

    An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs during serialization of DollarBlend in a font, for base/write_t1.c and psi/zfapi.c.

  • CVE-2025-27835Mar 25, 2025
    risk 0.00cvss epss 0.00

    An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs when converting glyphs to Unicode in psi/zbfont.c.

  • CVE-2025-27832Mar 25, 2025
    risk 0.00cvss epss 0.01

    An issue was discovered in Artifex Ghostscript before 10.05.0. The NPDL device has a Compression buffer overflow for contrib/japanese/gdevnpdl.c.

  • CVE-2025-27834Mar 25, 2025
    risk 0.00cvss epss 0.00

    An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs via an oversized Type 4 function in a PDF document to pdf/pdf_func.c.

  • CVE-2024-46956Nov 10, 2024
    risk 0.00cvss epss 0.00

    An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.

  • CVE-2024-46955Nov 10, 2024
    risk 0.00cvss epss 0.00

    An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space.

  • CVE-2024-46952Nov 10, 2024
    risk 0.00cvss epss 0.00

    An issue was discovered in pdf/pdf_xref.c in Artifex Ghostscript before 10.04.0. There is a buffer overflow during handling of a PDF XRef stream (related to W array values).

  • CVE-2024-46953Nov 10, 2024
    risk 0.00cvss epss 0.00

    An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.

  • CVE-2024-46951Nov 10, 2024
    risk 0.00cvss epss 0.00

    An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.

  • CVE-2024-46954Nov 10, 2024
    risk 0.00cvss epss 0.01

    An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.

Page 4 of 8