Artifex

Ghostscript

133 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.35%
  • Veröffentlicht 01.08.2023 17:15:09
  • Zuletzt bearbeitet 21.11.2024 08:13:49

An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local attacker to cause a denial of service via transforming a crafted PCL file to PDF format.

  • EPSS 3.24%
  • Veröffentlicht 25.06.2023 22:15:21
  • Zuletzt bearbeitet 28.08.2026 16:16:49

Artifex Ghostscript before 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).

Exploit
  • EPSS 6.34%
  • Veröffentlicht 31.03.2023 17:15:06
  • Zuletzt bearbeitet 14.02.2025 20:15:33

In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is f...

  • EPSS 0.46%
  • Veröffentlicht 19.08.2022 23:15:08
  • Zuletzt bearbeitet 30.04.2025 10:15:15

A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could l...

Exploit
  • EPSS 1.43%
  • Veröffentlicht 16.06.2022 18:15:10
  • Zuletzt bearbeitet 21.11.2024 07:00:17

A NULL pointer dereference vulnerability was found in Ghostscript, which occurs when it tries to render a large number of bits in memory. When allocating a buffer device, it relies on an init_device_procs defined for the device that uses it as a prot...

  • EPSS 1.12%
  • Veröffentlicht 25.04.2022 04:15:07
  • Zuletzt bearbeitet 21.11.2024 04:39:51

Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.

  • EPSS 83.91%
  • Veröffentlicht 16.02.2022 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:22:24

A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the...

Exploit
  • EPSS 1.36%
  • Veröffentlicht 01.01.2022 00:15:08
  • Zuletzt bearbeitet 21.11.2024 06:33:19

Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp).

Exploit
  • EPSS 1.4%
  • Veröffentlicht 01.01.2022 00:15:08
  • Zuletzt bearbeitet 08.10.2026 01:16:31

Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).

Exploit
  • EPSS 0.45%
  • Veröffentlicht 03.09.2020 18:15:13
  • Zuletzt bearbeitet 21.11.2024 05:03:07

A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25. A local attacker could supply a specially crafted PDF file to cause a denial of service.