VYPR

Ghostscript

by The Ghostscript Project

CVEs (14)

  • CVE-2016-7976HigAug 7, 2017
    risk 0.64cvss 8.8epss 0.47

    The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.

  • CVE-2016-7979CriMay 23, 2017
    risk 0.64cvss 9.8epss 0.03

    Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code by leveraging type confusion in .initialize_dsc_parser.

  • CVE-2016-7978CriMay 23, 2017
    risk 0.64cvss 9.8epss 0.03

    Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors related to a reference leak in .setdevice.

  • CVE-2016-8602HigApr 14, 2017
    risk 0.51cvss 7.8epss 0.01

    The .sethalftone5 function in psi/zht2.c in Ghostscript before 9.21 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Postscript document that calls .sethalftone5 with an empty operand stack.

  • CVE-2016-10317HigApr 3, 2017
    risk 0.51cvss 7.8epss 0.01

    The fill_threshhold_buffer function in base/gxht_thresh.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PostScript…

  • CVE-2016-7977MedMay 23, 2017
    risk 0.36cvss 5.5epss 0.01

    Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use of the .libfile operator in a crafted postscript document.

  • CVE-2016-10220MedApr 3, 2017
    risk 0.36cvss 5.5epss 0.01

    The gs_makewordimagedevice function in base/gsdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file that is mishandled in the PDF Transparency module.

  • CVE-2016-10219MedApr 3, 2017
    risk 0.36cvss 5.5epss 0.01

    The intersect function in base/gxfill.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.

  • CVE-2016-10218MedApr 3, 2017
    risk 0.36cvss 5.5epss 0.00

    The pdf14_pop_transparency_group function in base/gdevp14.c in the PDF Transparency module in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.

  • CVE-2016-10217MedApr 3, 2017
    risk 0.36cvss 5.5epss 0.01

    The pdf14_open function in base/gdevp14.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted file that is mishandled in the color management module.

  • CVE-2013-5653MedMar 7, 2017
    risk 0.36cvss 5.5epss 0.00

    The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER" argument, which allows remote attackers to read data via a crafted postscript file.

  • CVE-2019-3839May 16, 2019
    risk 0.00cvss epss 0.00

    It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by…

  • CVE-2019-3835Mar 25, 2019
    risk 0.00cvss epss 0.02

    It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.

  • CVE-2019-3838Mar 25, 2019
    risk 0.00cvss epss 0.01

    It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.