CVE-2022-2085
- EPSS 0.19%
- Veröffentlicht 16.06.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 07:00:17
A NULL pointer dereference vulnerability was found in Ghostscript, which occurs when it tries to render a large number of bits in memory. When allocating a buffer device, it relies on an init_device_procs defined for the device that uses it as a prot...
CVE-2019-25059
- EPSS 0.18%
- Veröffentlicht 25.04.2022 04:15:07
- Zuletzt bearbeitet 21.11.2024 04:39:51
Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
CVE-2021-3781
- EPSS 9.27%
- Veröffentlicht 16.02.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:24
A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the...
CVE-2021-45944
- EPSS 0.3%
- Veröffentlicht 01.01.2022 00:15:08
- Zuletzt bearbeitet 21.11.2024 06:33:19
Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp).
CVE-2021-45949
- EPSS 0.06%
- Veröffentlicht 01.01.2022 00:15:08
- Zuletzt bearbeitet 21.11.2024 06:33:20
Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).
CVE-2020-14373
- EPSS 0.13%
- Veröffentlicht 03.09.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:03:07
A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25. A local attacker could supply a specially crafted PDF file to cause a denial of service.
CVE-2020-16304
- EPSS 0.47%
- Veröffentlicht 13.08.2020 03:15:14
- Zuletzt bearbeitet 14.03.2025 18:27:22
A buffer overflow vulnerability in image_render_color_thresh() in base/gxicolor.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to escalate privileges via a crafted eps file. This is fixed in v9.51.
CVE-2020-16305
- EPSS 0.57%
- Veröffentlicht 13.08.2020 03:15:14
- Zuletzt bearbeitet 21.11.2024 05:07:08
A buffer overflow vulnerability in pcx_write_rle() in contrib/japanese/gdev10v.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
CVE-2020-16306
- EPSS 1.77%
- Veröffentlicht 13.08.2020 03:15:14
- Zuletzt bearbeitet 21.11.2024 05:07:09
A null pointer dereference vulnerability in devices/gdevtsep.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fixed in v9.51.
CVE-2020-16307
- EPSS 1.77%
- Veröffentlicht 13.08.2020 03:15:14
- Zuletzt bearbeitet 21.11.2024 05:07:09
A null pointer dereference vulnerability in devices/vector/gdevtxtw.c and psi/zbfont.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fixed in v9.51.