Artifex Gpl Ghostscript vulnerabilities
16 known vulnerabilities affecting artifex/gpl_ghostscript.
Total CVEs
16
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH8MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2018-18284HIGHCVSS 8.6fixed in 9.262018-10-19
CVE-2018-18284 [HIGH] CVE-2018-18284: Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via v
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator.
nvd
CVE-2018-16513HIGHCVSS 7.8fixed in 9.262018-09-05
CVE-2018-16513 [HIGH] CWE-704 CVE-2018-16513: In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a ty
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the setcolor function to crash the interpreter or possibly have unspecified other impact.
nvd
CVE-2018-16509HIGHCVSS 7.8ExploitedPoCfixed in 9.262018-09-05
CVE-2018-16509 [HIGH] CWE-184 CVE-2018-16509: An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" che
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction.
nvd
CVE-2018-16510HIGHCVSS 7.8fixed in 9.262018-09-05
CVE-2018-16510 [HIGH] CWE-119 CVE-2018-16510: An issue was discovered in Artifex Ghostscript before 9.24. Incorrect exec stack handling in the "CS
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect exec stack handling in the "CS" and "SC" PDF primitives could be used by remote attackers able to supply crafted PDFs to crash the interpreter or possibly have unspecified other impact.
nvd
CVE-2018-15911HIGHCVSS 7.8fixed in 9.262018-08-28
CVE-2018-15911 [HIGH] CWE-908 CVE-2018-15911: In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use
In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode operator to crash the interpreter or potentially execute code.
nvd
CVE-2018-15909HIGHCVSS 7.8fixed in 9.262018-08-27
CVE-2018-15909 [HIGH] CWE-704 CVE-2018-15909: In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be
In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScript files to crash the interpreter or potentially execute code.
nvd
CVE-2018-15910HIGHCVSS 7.8fixed in 9.262018-08-27
CVE-2018-15910 [HIGH] CWE-704 CVE-2018-15910: In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a ty
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the LockDistillerParams parameter to crash the interpreter or execute code.
nvd
CVE-2016-9601MEDIUMCVSS 5.5fixed in 9.212018-04-24
CVE-2016-9601 [MEDIUM] CWE-190 CVE-2016-9601: ghostscript before version 9.21 is vulnerable to a heap based buffer overflow that was found in the
ghostscript before version 9.21 is vulnerable to a heap based buffer overflow that was found in the ghostscript jbig2_decode_gray_scale_image function which is used to decode halftone segments in a JBIG2 image. A document (PostScript or PDF) with an embedded, specially crafted, jbig2 image could trigger a segmentation fault in ghostscript.
nvd
CVE-2013-6629MEDIUMCVSS 5.0fixed in 9.032013-11-19
CVE-2013-6629 [MEDIUM] CWE-200 CVE-2013-6629: The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in
The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive
nvd
CVE-2012-4875CRITICALCVSS 9.3v9.042012-09-06
CVE-2012-4875 [CRITICAL] CWE-119 CVE-2012-4875: Heap-based buffer overflow in gdevwpr2.c in Ghostscript 9.04, when processing the OutputFile device
Heap-based buffer overflow in gdevwpr2.c in Ghostscript 9.04, when processing the OutputFile device parameter, allows user-assisted remote attackers to execute arbitrary code via a long file name in a PostScript document. NOTE: as of 20120314, the developer was not able to reproduce the issue and disputed it
nvd
CVE-2010-4054MEDIUMCVSS 4.3v8.01v8.15+12 more2010-10-23
CVE-2010-4054 [MEDIUM] CWE-119 CVE-2010-4054: The gs_type2_interpret function in Ghostscript allows remote attackers to cause a denial of service
The gs_type2_interpret function in Ghostscript allows remote attackers to cause a denial of service (incorrect pointer dereference and application crash) via crafted font data in a compressed data stream, aka bug 691043.
nvd
CVE-2009-3743CRITICALCVSS 9.3≤ 8.70v8.01+11 more2010-08-26
CVE-2009-3743 [CRITICAL] CWE-189 CVE-2009-3743: Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript befo
Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer overflow.
nvd
CVE-2009-4897CRITICALCVSS 9.3≤ 8.64v8.01+12 more2010-07-22
CVE-2009-4897 [CRITICAL] CWE-119 CVE-2009-4897: Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote attackers to execute
Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document containing a long name.
nvd
CVE-2010-2055HIGHCVSS 7.2≤ 8.71v8.01+12 more2010-07-22
CVE-2010-2055 [HIGH] CWE-17 CVE-2010-2055: Ghostscript 8.71 and earlier reads initialization files from the current working directory, which al
Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program, as demonstrated using gs_init.ps, a different vulnerability than CVE-2010-4820.
nvd
CVE-2010-1628CRITICALCVSS 9.3v8.64v8.702010-05-19
CVE-2010-1628 [CRITICAL] CWE-119 CVE-2010-1628: Ghostscript 8.64, 8.70, and possibly other versions allows context-dependent attackers to execute ar
Ghostscript 8.64, 8.70, and possibly other versions allows context-dependent attackers to execute arbitrary code via a PostScript file containing unlimited recursive procedure invocations, which trigger memory corruption in the stack of the interpreter.
nvd
CVE-2010-1869CRITICALCVSS 9.3PoCv8.64v8.702010-05-12
CVE-2010-1869 [CRITICAL] CWE-119 CVE-2010-1869: Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-depen
Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a crafted PostScript file.
nvd