CVE-2018-15908
- EPSS 1.92%
- Veröffentlicht 27.08.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:51:41
In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript files to bypass .tempfile restrictions and write files.
CVE-2018-15909
- EPSS 3.02%
- Veröffentlicht 27.08.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:51:41
In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScript files to crash the interpreter or potentially execute code.
CVE-2018-15910
- EPSS 3.04%
- Veröffentlicht 27.08.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:51:42
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the LockDistillerParams parameter to crash the interpreter or execute code.
CVE-2018-11645
- EPSS 2.58%
- Veröffentlicht 01.06.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 03:43:45
psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a similar issue to CVE-2016-7977.
CVE-2018-10194
- EPSS 1.91%
- Veröffentlicht 18.04.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:59
The set_text_distance function in devices/vector/gdevpdts.c in the pdfwrite component in Artifex Ghostscript through 9.22 does not prevent overflows in text-positioning calculation, which allows remote attackers to cause a denial of service (applicat...
CVE-2016-7976
- EPSS 23.45%
- Veröffentlicht 07.08.2017 20:29:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.
CVE-2017-11714
- EPSS 2.3%
- Veröffentlicht 28.07.2017 05:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
psi/ztoken.c in Artifex Ghostscript 9.21 mishandles references to the scanner state structure, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PostScript document,...
CVE-2017-9611
- EPSS 1.95%
- Veröffentlicht 26.07.2017 19:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The Ins_MIRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document.
CVE-2017-9835
- EPSS 2.69%
- Veröffentlicht 26.07.2017 19:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The gs_alloc_ref_array function in psi/ialloc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PostScript doc...
CVE-2016-7977
- EPSS 4.57%
- Veröffentlicht 23.05.2017 04:29:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use of the .libfile operator in a crafted postscript document.