CVE-2023-38560
- EPSS 0.35%
- Veröffentlicht 01.08.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 08:13:49
An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local attacker to cause a denial of service via transforming a crafted PCL file to PDF format.
CVE-2023-36664
- EPSS 3.24%
- Veröffentlicht 25.06.2023 22:15:21
- Zuletzt bearbeitet 28.08.2026 16:16:49
Artifex Ghostscript before 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
CVE-2023-28879
- EPSS 6.34%
- Veröffentlicht 31.03.2023 17:15:06
- Zuletzt bearbeitet 14.02.2025 20:15:33
In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is f...
CVE-2020-27792
- EPSS 0.46%
- Veröffentlicht 19.08.2022 23:15:08
- Zuletzt bearbeitet 30.04.2025 10:15:15
A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could l...
CVE-2022-2085
- EPSS 1.43%
- Veröffentlicht 16.06.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 07:00:17
A NULL pointer dereference vulnerability was found in Ghostscript, which occurs when it tries to render a large number of bits in memory. When allocating a buffer device, it relies on an init_device_procs defined for the device that uses it as a prot...
CVE-2019-25059
- EPSS 1.12%
- Veröffentlicht 25.04.2022 04:15:07
- Zuletzt bearbeitet 21.11.2024 04:39:51
Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
CVE-2021-3781
- EPSS 83.91%
- Veröffentlicht 16.02.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:24
A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the...
CVE-2021-45944
- EPSS 1.36%
- Veröffentlicht 01.01.2022 00:15:08
- Zuletzt bearbeitet 21.11.2024 06:33:19
Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp).
CVE-2021-45949
- EPSS 1.4%
- Veröffentlicht 01.01.2022 00:15:08
- Zuletzt bearbeitet 08.10.2026 01:16:31
Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).
CVE-2020-14373
- EPSS 0.45%
- Veröffentlicht 03.09.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:03:07
A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25. A local attacker could supply a specially crafted PDF file to cause a denial of service.