Artifex

Ghostscript

133 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 5.53%
  • Veröffentlicht 23.05.2017 04:29:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors related to a reference leak in .setdevice.

  • EPSS 6.42%
  • Veröffentlicht 23.05.2017 04:29:01
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code by leveraging type confusion in .initialize_dsc_parser.

  • EPSS 1.15%
  • Veröffentlicht 12.05.2017 07:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The mark_line_tr function in gxscanc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PostScript document.

Warnung Exploit
  • EPSS 96.14%
  • Veröffentlicht 27.04.2017 01:59:02
  • Zuletzt bearbeitet 21.04.2026 18:02:58

Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs program, as exploited in the wild in ...

Exploit
  • EPSS 1.62%
  • Veröffentlicht 19.04.2017 14:59:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Integer overflow in the mark_curve function in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via a crafted PostScript document.

  • EPSS 3.21%
  • Veröffentlicht 14.04.2017 18:59:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The .sethalftone5 function in psi/zht2.c in Ghostscript before 9.21 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Postscript document that calls .sethalftone5 with an empty o...

Exploit
  • EPSS 2.28%
  • Veröffentlicht 03.04.2017 20:59:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The fill_threshhold_buffer function in base/gxht_thresh.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via...

Exploit
  • EPSS 1.46%
  • Veröffentlicht 03.04.2017 05:59:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The pdf14_open function in base/gdevp14.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted file that is mishandled in the color management module.

Exploit
  • EPSS 1.27%
  • Veröffentlicht 03.04.2017 05:59:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The pdf14_pop_transparency_group function in base/gdevp14.c in the PDF Transparency module in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ...

Exploit
  • EPSS 1.86%
  • Veröffentlicht 03.04.2017 05:59:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The intersect function in base/gxfill.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.