VYPR

Ghostscript

by Artifex

Source repositories

CVEs (163)

  • CVE-2020-16295MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.02

    A null pointer dereference vulnerability in clj_media_size() in devices/gdevclj.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

  • CVE-2020-16294MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.02

    A buffer overflow vulnerability in epsc_print_page() in devices/gdevepsc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

  • CVE-2020-16293MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.02

    A null pointer dereference vulnerability in compose_group_nonknockout_nonblend_isolated_allmask_common() in base/gxblend.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

  • CVE-2020-16292MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.02

    A buffer overflow vulnerability in mj_raster_cmd() in contrib/japanese/gdevmjc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

  • CVE-2020-16291MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.02

    A buffer overflow vulnerability in contrib/gdevdj9.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

  • CVE-2020-16290MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.02

    A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

  • CVE-2020-16289MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.02

    A buffer overflow vulnerability in cif_print_page() in devices/gdevcif.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

  • CVE-2020-16288MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.02

    A buffer overflow vulnerability in pj_common_print_page() in devices/gdevpjet.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

  • CVE-2020-16287MedAug 13, 2020
    risk 0.36cvss 5.5epss 0.02

    A buffer overflow vulnerability in lprn_is_black() in contrib/lips4/gdevlprn.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

  • CVE-2017-15652MedMay 23, 2019
    risk 0.36cvss 5.5epss 0.01

    Artifex Ghostscript 9.22 is affected by: Obtain Information. The impact is: obtain sensitive information. The component is: affected source code file, affected function, affected executable, affected libga (imagemagick used that). The attack vector is: Someone must open a…

  • CVE-2019-3838MedMar 25, 2019
    risk 0.36cvss 5.5epss 0.03

    It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.

  • CVE-2019-3835MedMar 25, 2019
    risk 0.36cvss 5.5epss 0.03

    It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.

  • CVE-2018-19478MedJan 2, 2019
    risk 0.36cvss 5.5epss 0.02

    In Artifex Ghostscript before 9.26, a carefully crafted PDF file can trigger an extremely long running computation when parsing the file.

  • CVE-2018-16542MedSep 5, 2018
    risk 0.36cvss 5.5epss 0.02

    In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use insufficient interpreter stack-size checking during error handling to crash the interpreter.

  • CVE-2018-16541MedSep 5, 2018
    risk 0.36cvss 5.5epss 0.01

    In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect free logic in pagedevice replacement to crash the interpreter.

  • CVE-2018-16539MedSep 5, 2018
    risk 0.36cvss 5.5epss 0.01

    In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect access checking in temp file handling to disclose contents of files on the system otherwise not readable.

  • CVE-2016-7977MedMay 23, 2017
    risk 0.36cvss 5.5epss 0.05

    Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use of the .libfile operator in a crafted postscript document.

  • CVE-2017-8908MedMay 12, 2017
    risk 0.36cvss 5.5epss 0.01

    The mark_line_tr function in gxscanc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PostScript document.

  • CVE-2017-5951MedApr 3, 2017
    risk 0.36cvss 5.5epss 0.02

    The mem_get_bits_rectangle function in base/gdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.

  • CVE-2016-10220MedApr 3, 2017
    risk 0.36cvss 5.5epss 0.02

    The gs_makewordimagedevice function in base/gsdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file that is mishandled in the PDF Transparency module.

Page 6 of 9