Artifex

Ghostscript

133 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.3%
  • Veröffentlicht 10.11.2024 22:15:12
  • Zuletzt bearbeitet 03.11.2025 23:16:11

An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space.

  • EPSS 0.39%
  • Veröffentlicht 10.11.2024 22:15:12
  • Zuletzt bearbeitet 03.11.2025 23:16:12

An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.

  • EPSS 0.36%
  • Veröffentlicht 10.11.2024 21:15:14
  • Zuletzt bearbeitet 03.11.2025 23:16:11

An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.

  • EPSS 0.72%
  • Veröffentlicht 03.07.2024 19:15:03
  • Zuletzt bearbeitet 28.04.2025 17:12:33

Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.

Exploit
  • EPSS 27.97%
  • Veröffentlicht 03.07.2024 19:15:03
  • Zuletzt bearbeitet 28.04.2025 17:12:24

Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.

  • EPSS 1.14%
  • Veröffentlicht 03.07.2024 19:15:03
  • Zuletzt bearbeitet 28.04.2025 17:12:15

Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /t...

  • EPSS 0.45%
  • Veröffentlicht 03.07.2024 19:15:03
  • Zuletzt bearbeitet 16.04.2025 19:14:53

An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of %pipe% can be bypassed v...

  • EPSS 0.52%
  • Veröffentlicht 03.07.2024 19:15:03
  • Zuletzt bearbeitet 16.04.2025 19:14:47

An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo ...

  • EPSS 1.43%
  • Veröffentlicht 03.07.2024 19:15:03
  • Zuletzt bearbeitet 16.04.2025 19:14:28

An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the Driver parameter for opvp (and ...

  • EPSS 0.91%
  • Veröffentlicht 03.07.2024 18:15:04
  • Zuletzt bearbeitet 21.11.2024 09:08:05

Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name.