Artifex

Ghostscript

129 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.19%
  • Veröffentlicht 16.06.2022 18:15:10
  • Zuletzt bearbeitet 21.11.2024 07:00:17

A NULL pointer dereference vulnerability was found in Ghostscript, which occurs when it tries to render a large number of bits in memory. When allocating a buffer device, it relies on an init_device_procs defined for the device that uses it as a prot...

  • EPSS 0.18%
  • Veröffentlicht 25.04.2022 04:15:07
  • Zuletzt bearbeitet 21.11.2024 04:39:51

Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.

  • EPSS 9.27%
  • Veröffentlicht 16.02.2022 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:22:24

A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 01.01.2022 00:15:08
  • Zuletzt bearbeitet 21.11.2024 06:33:19

Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp).

Exploit
  • EPSS 0.06%
  • Veröffentlicht 01.01.2022 00:15:08
  • Zuletzt bearbeitet 21.11.2024 06:33:20

Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).

Exploit
  • EPSS 0.13%
  • Veröffentlicht 03.09.2020 18:15:13
  • Zuletzt bearbeitet 21.11.2024 05:03:07

A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25. A local attacker could supply a specially crafted PDF file to cause a denial of service.

Exploit
  • EPSS 0.47%
  • Veröffentlicht 13.08.2020 03:15:14
  • Zuletzt bearbeitet 14.03.2025 18:27:22

A buffer overflow vulnerability in image_render_color_thresh() in base/gxicolor.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to escalate privileges via a crafted eps file. This is fixed in v9.51.

Exploit
  • EPSS 0.57%
  • Veröffentlicht 13.08.2020 03:15:14
  • Zuletzt bearbeitet 21.11.2024 05:07:08

A buffer overflow vulnerability in pcx_write_rle() in contrib/japanese/gdev10v.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

Exploit
  • EPSS 1.77%
  • Veröffentlicht 13.08.2020 03:15:14
  • Zuletzt bearbeitet 21.11.2024 05:07:09

A null pointer dereference vulnerability in devices/gdevtsep.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fixed in v9.51.

Exploit
  • EPSS 1.77%
  • Veröffentlicht 13.08.2020 03:15:14
  • Zuletzt bearbeitet 21.11.2024 05:07:09

A null pointer dereference vulnerability in devices/vector/gdevtxtw.c and psi/zbfont.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fixed in v9.51.