Artifex

Ghostscript

133 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.44%
  • Veröffentlicht 30.09.2026 14:15:06
  • Zuletzt bearbeitet 30.09.2026 16:11:29

A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation leads to stack-based buffer overflow. Remote exploitation o...

  • EPSS 0.16%
  • Veröffentlicht 29.09.2026 10:17:11
  • Zuletzt bearbeitet 30.09.2026 19:38:27

Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource file hijacking. Due to the application searching for PostScript resource files in predictable paths under C:\\gs\\ that do not exist by default on Windows...

Medienbericht
  • EPSS 0.49%
  • Veröffentlicht 15.09.2026 14:26:06
  • Zuletzt bearbeitet 24.09.2026 21:04:40

Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 image with mismat...

  • EPSS 0.43%
  • Veröffentlicht 09.07.2026 00:00:00
  • Zuletzt bearbeitet 14.09.2026 14:17:07

An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • EPSS 0.19%
  • Veröffentlicht 22.09.2025 00:00:00
  • Zuletzt bearbeitet 03.11.2025 18:17:01

Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdfmark_coerce_dest in devices/vector/gdevpdfm.c via a large size value.

  • EPSS 0.17%
  • Veröffentlicht 22.09.2025 00:00:00
  • Zuletzt bearbeitet 25.09.2025 19:27:49

In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8.

  • EPSS 0.19%
  • Veröffentlicht 22.09.2025 00:00:00
  • Zuletzt bearbeitet 03.11.2025 18:17:01

Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c.

  • EPSS 0.3%
  • Veröffentlicht 23.05.2025 00:00:00
  • Zuletzt bearbeitet 24.05.2025 01:15:19

gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.

  • EPSS 0.18%
  • Veröffentlicht 26.04.2025 00:00:00
  • Zuletzt bearbeitet 23.06.2025 18:36:04

In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954.

Medienbericht
  • EPSS 0.28%
  • Veröffentlicht 25.03.2025 00:00:00
  • Zuletzt bearbeitet 03.11.2025 20:18:07

An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs during serialization of DollarBlend in a font, for base/write_t1.c and psi/zfapi.c.