VYPR

Ghostscript

by Artifex

Source repositories

CVEs (163)

  • CVE-2009-3743Aug 26, 2010
    risk 0.01cvss epss 0.07

    Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer…

  • CVE-2009-4897Jul 22, 2010
    risk 0.01cvss epss 0.07

    Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document containing a long name.

  • CVE-2009-4270Dec 21, 2009
    risk 0.01cvss epss 0.07

    Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghostscript 8.64 through 8.70 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file, as originally reported for debug logging code in…

  • CVE-2009-0196Apr 16, 2009
    risk 0.01cvss epss 0.07

    Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute arbitrary code via a PDF file with a JBIG2 symbol dictionary…

  • CVE-2020-15900CriJul 28, 2020
    risk 0.00cvss 9.8epss 0.05

    A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and could underflow to max…

  • CVE-2015-3228Aug 11, 2015
    risk 0.00cvss epss 0.04

    Integer overflow in the gs_heap_alloc_bytes function in base/gsmalloc.c in Ghostscript 9.15 and earlier allows remote attackers to cause a denial of service (crash) via a crafted Postscript (ps) file, as demonstrated by using the ps2pdf command, which triggers an out-of-bounds…

  • CVE-2010-4820Oct 27, 2014
    risk 0.00cvss epss 0.00

    Untrusted search path vulnerability in Ghostscript 8.62 allows local users to execute arbitrary PostScript code via a Trojan horse Postscript library file in Encoding/ under the current working directory, a different vulnerability than CVE-2010-2055.

  • CVE-2012-4875Sep 6, 2012
    risk 0.00cvss epss 0.04

    Heap-based buffer overflow in gdevwpr2.c in Ghostscript 9.04, when processing the OutputFile device parameter, allows user-assisted remote attackers to execute arbitrary code via a long file name in a PostScript document. NOTE: as of 20120314, the developer was not able to…

  • CVE-2010-4054Oct 23, 2010
    risk 0.00cvss epss 0.03

    The gs_type2_interpret function in Ghostscript allows remote attackers to cause a denial of service (incorrect pointer dereference and application crash) via crafted font data in a compressed data stream, aka bug 691043.

  • CVE-2010-2055Jul 22, 2010
    risk 0.00cvss epss 0.01

    Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program, as demonstrated using…

  • CVE-2010-1628May 19, 2010
    risk 0.00cvss epss 0.04

    Ghostscript 8.64, 8.70, and possibly other versions allows context-dependent attackers to execute arbitrary code via a PostScript file containing unlimited recursive procedure invocations, which trigger memory corruption in the stack of the interpreter.

  • CVE-2009-0792Apr 14, 2009
    risk 0.00cvss epss 0.04

    Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service…

  • CVE-2008-6679Apr 8, 2009
    risk 0.00cvss epss 0.04

    Buffer overflow in the BaseFont writer module in Ghostscript 8.62, and possibly other versions, allows remote attackers to cause a denial of service (ps2pdf crash) and possibly execute arbitrary code via a crafted Postscript file.

  • CVE-2007-6725Apr 8, 2009
    risk 0.00cvss epss 0.05

    The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file that triggers a buffer underflow in the cf_decode_2d function.

  • CVE-2009-0584Mar 23, 2009
    risk 0.00cvss epss 0.04

    icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service (application crash) or possibly…

  • CVE-2009-0583Mar 23, 2009
    risk 0.00cvss epss 0.05

    Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service…

  • CVE-2004-0967Feb 9, 2005
    risk 0.00cvss epss 0.00

    The (1) pj-gs.sh, (2) ps2epsi, (3) pv.sh, and (4) sysvlp.sh scripts in the ESP Ghostscript (espgs) package in Trustix Secure Linux 1.5 through 2.1, and other operating systems, allow local users to overwrite files via a symlink attack on temporary files.

  • CVE-2003-0354Jun 16, 2003
    risk 0.00cvss epss 0.02

    Unknown vulnerability in GNU Ghostscript before 7.07 allows attackers to execute arbitrary commands, even when -dSAFER is enabled, via a PostScript file that causes the commands to be executed from a malicious print job.

  • CVE-2002-0363May 29, 2002
    risk 0.00cvss epss 0.02

    ghostscript before 6.53 allows attackers to execute arbitrary commands by using .locksafe or .setsafe to reset the current pagedevice.

  • CVE-2001-1353Sep 18, 2001
    risk 0.00cvss epss 0.00

    ghostscript before 6.51 allows local users to read and write arbitrary files as the 'lp' user via the file operator, even with -dSAFER enabled.

Page 8 of 9