Artifex

Ghostscript

129 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.56%
  • Published 13.08.2020 03:15:12
  • Last modified 04.03.2025 19:15:36

A buffer overflow vulnerability in contrib/gdevdj9.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

  • EPSS 12.14%
  • Published 28.07.2020 16:15:12
  • Last modified 21.11.2024 05:06:24

A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and...

  • EPSS 0.55%
  • Published 27.11.2019 14:15:11
  • Last modified 21.11.2024 04:27:24

A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable...

  • EPSS 0.53%
  • Published 27.11.2019 13:15:10
  • Last modified 21.11.2024 04:18:40

In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that coul...

  • EPSS 0.27%
  • Published 15.11.2019 12:15:10
  • Last modified 21.11.2024 04:27:32

A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating ...

  • EPSS 8.45%
  • Published 06.09.2019 14:15:15
  • Last modified 21.11.2024 04:27:24

A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable se...

Exploit
  • EPSS 1.36%
  • Published 03.09.2019 16:15:11
  • Last modified 21.11.2024 04:27:24

A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disabl...

Exploit
  • EPSS 0.36%
  • Published 03.09.2019 16:15:11
  • Last modified 21.11.2024 04:27:25

A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could dis...

Exploit
  • EPSS 0.27%
  • Published 23.05.2019 15:29:00
  • Last modified 21.11.2024 03:14:57

Artifex Ghostscript 9.22 is affected by: Obtain Information. The impact is: obtain sensitive information. The component is: affected source code file, affected function, affected executable, affected libga (imagemagick used that). The attack vector i...

  • EPSS 0.18%
  • Published 16.05.2019 19:29:05
  • Last modified 21.11.2024 04:42:40

It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside o...