CVE-2024-46955
- EPSS 0.3%
- Veröffentlicht 10.11.2024 22:15:12
- Zuletzt bearbeitet 03.11.2025 23:16:11
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space.
CVE-2024-46956
- EPSS 0.39%
- Veröffentlicht 10.11.2024 22:15:12
- Zuletzt bearbeitet 03.11.2025 23:16:12
An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.
CVE-2024-46951
- EPSS 0.36%
- Veröffentlicht 10.11.2024 21:15:14
- Zuletzt bearbeitet 03.11.2025 23:16:11
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.
CVE-2024-29507
- EPSS 0.72%
- Veröffentlicht 03.07.2024 19:15:03
- Zuletzt bearbeitet 28.04.2025 17:12:33
Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.
CVE-2024-29510
- EPSS 27.97%
- Veröffentlicht 03.07.2024 19:15:03
- Zuletzt bearbeitet 28.04.2025 17:12:24
Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.
CVE-2024-29511
- EPSS 1.14%
- Veröffentlicht 03.07.2024 19:15:03
- Zuletzt bearbeitet 28.04.2025 17:12:15
Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /t...
CVE-2024-33869
- EPSS 0.45%
- Veröffentlicht 03.07.2024 19:15:03
- Zuletzt bearbeitet 16.04.2025 19:14:53
An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of %pipe% can be bypassed v...
CVE-2024-33870
- EPSS 0.52%
- Veröffentlicht 03.07.2024 19:15:03
- Zuletzt bearbeitet 16.04.2025 19:14:47
An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo ...
CVE-2024-33871
- EPSS 1.43%
- Veröffentlicht 03.07.2024 19:15:03
- Zuletzt bearbeitet 16.04.2025 19:14:28
An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the Driver parameter for opvp (and ...
CVE-2024-29506
- EPSS 0.91%
- Veröffentlicht 03.07.2024 18:15:04
- Zuletzt bearbeitet 21.11.2024 09:08:05
Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name.