Artifex Ghostscript vulnerabilities

168 known vulnerabilities affecting artifex/ghostscript.

Total CVEs
168
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
2
Severity breakdown
CRITICAL23HIGH70MEDIUM73LOW2

Vulnerabilities

Page 6 of 9
CVE-2018-16540HIGHCVSS 7.8fixed in 9.242018-09-05
CVE-2018-16540 [HIGH] CWE-416 CVE-2018-16540: In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified other impact.
nvdosv
CVE-2018-16511HIGHCVSS 7.8fixed in 9.242018-09-05
CVE-2018-16511 [HIGH] CWE-704 CVE-2018-16511: An issue was discovered in Artifex Ghostscript before 9.24. A type confusion in "ztype" could be use An issue was discovered in Artifex Ghostscript before 9.24. A type confusion in "ztype" could be used by remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact.
nvdosv
CVE-2018-16509HIGHCVSS 7.8ExploitedPoCfixed in 9.24v9.072018-09-05
CVE-2018-16509 [HIGH] CWE-184 CVE-2018-16509: An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" che An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction.
nvdosv
CVE-2018-16543HIGHCVSS 7.8fixed in 9.242018-09-05
CVE-2018-16543 [HIGH] CVE-2018-16543: In Artifex Ghostscript before 9.24, gssetresolution and gsgetresolution allow attackers to have an u In Artifex Ghostscript before 9.24, gssetresolution and gsgetresolution allow attackers to have an unspecified impact.
nvdosv
CVE-2018-16513HIGHCVSS 7.8fixed in 9.242018-09-05
CVE-2018-16513 [HIGH] CWE-704 CVE-2018-16513: In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a ty In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the setcolor function to crash the interpreter or possibly have unspecified other impact.
nvdosv
CVE-2018-16510HIGHCVSS 7.8fixed in 9.242018-09-05
CVE-2018-16510 [HIGH] CWE-119 CVE-2018-16510: An issue was discovered in Artifex Ghostscript before 9.24. Incorrect exec stack handling in the "CS An issue was discovered in Artifex Ghostscript before 9.24. Incorrect exec stack handling in the "CS" and "SC" PDF primitives could be used by remote attackers able to supply crafted PDFs to crash the interpreter or possibly have unspecified other impact.
nvdosv
CVE-2018-16542MEDIUMCVSS 5.5fixed in 9.242018-09-05
CVE-2018-16542 [MEDIUM] CWE-787 CVE-2018-16542: In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use insu In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use insufficient interpreter stack-size checking during error handling to crash the interpreter.
nvdosv
CVE-2018-16541MEDIUMCVSS 5.5fixed in 9.242018-09-05
CVE-2018-16541 [MEDIUM] CWE-416 CVE-2018-16541: In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use inco In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect free logic in pagedevice replacement to crash the interpreter.
nvdosv
CVE-2018-16539MEDIUMCVSS 5.5fixed in 9.242018-09-05
CVE-2018-16539 [MEDIUM] CWE-200 CVE-2018-16539: In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use inco In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect access checking in temp file handling to disclose contents of files on the system otherwise not readable.
nvdosv
CVE-2018-15911HIGHCVSS 7.8≤ 9.232018-08-28
CVE-2018-15911 [HIGH] CWE-908 CVE-2018-15911: In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode operator to crash the interpreter or potentially execute code.
nvdosv
CVE-2018-15909HIGHCVSS 7.8≤ 9.232018-08-27
CVE-2018-15909 [HIGH] CWE-704 CVE-2018-15909: In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScript files to crash the interpreter or potentially execute code.
nvdosv
CVE-2018-15910HIGHCVSS 7.8fixed in 9.242018-08-27
CVE-2018-15910 [HIGH] CWE-704 CVE-2018-15910: In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a ty In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the LockDistillerParams parameter to crash the interpreter or execute code.
nvdosv
CVE-2018-15908HIGHCVSS 7.8≤ 9.232018-08-27
CVE-2018-15908 [HIGH] CVE-2018-15908: In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript fil In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript files to bypass .tempfile restrictions and write files.
nvdosv
CVE-2018-11645MEDIUMCVSS 5.3≤ 9.202018-06-01
CVE-2018-11645 [MEDIUM] CVE-2018-11645: psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a similar issue to CVE-2016-7977.
nvdosv
CVE-2018-10194HIGHCVSS 7.8≤ 9.222018-04-18
CVE-2018-10194 [HIGH] CWE-119 CVE-2018-10194: The set_text_distance function in devices/vector/gdevpdts.c in the pdfwrite component in Artifex Gho The set_text_distance function in devices/vector/gdevpdts.c in the pdfwrite component in Artifex Ghostscript through 9.22 does not prevent overflows in text-positioning calculation, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.
nvdosv
CVE-2016-7976HIGHCVSS 8.8v9.18v9.202017-08-07
CVE-2016-7976 [HIGH] CWE-20 CVE-2016-7976: The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code vi The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.
nvdosv
CVE-2017-11714HIGHCVSS 7.8v9.212017-07-28
CVE-2017-11714 [HIGH] CWE-125 CVE-2017-11714: psi/ztoken.c in Artifex Ghostscript 9.21 mishandles references to the scanner state structure, which psi/ztoken.c in Artifex Ghostscript 9.21 mishandles references to the scanner state structure, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PostScript document, related to an out-of-bounds read in the igc_reloc_struct_ptr function in psi/igc.c.
nvdosv
CVE-2017-9611HIGHCVSS 7.8v9.212017-07-26
CVE-2017-9611 [HIGH] CWE-125 CVE-2017-9611: The Ins_MIRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attacker The Ins_MIRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document.
nvdosv
CVE-2017-9835HIGHCVSS 7.8v9.212017-07-26
CVE-2017-9835 [HIGH] CWE-190 CVE-2017-9835: The gs_alloc_ref_array function in psi/ialloc.c in Artifex Ghostscript 9.21 allows remote attackers The gs_alloc_ref_array function in psi/ialloc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PostScript document. This is related to a lack of an integer overflow check in base/gsalloc.c.
nvdosv
CVE-2017-9740HIGHCVSS 7.8≥ 0, < 9.22~dfsg-12017-07-26
CVE-2017-9740 [HIGH] CVE-2017-9740: The xps_decode_font_char_imp function in xps/xpsfont The xps_decode_font_char_imp function in xps/xpsfont.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document.
osv