cbcvebase.

Gnu Enscript vulnerabilities

7 known vulnerabilities affecting gnu/enscript.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM3LOW1

Vulnerabilities

Page 1 of 1
CVE-2008-3863P3HIGHCVSS 7.6v1.6.1v1.6.42008-10-23
CVE-2008-3863 [HIGH] CWE-119 CVE-2008-3863: Stack-based buffer overflow in the read_special_escape function in src/psgen.c in GNU Enscript 1.6.1 Stack-based buffer overflow in the read_special_escape function in src/psgen.c in GNU Enscript 1.6.1 and 1.6.4 beta, when the -e (aka special escapes processing) option is enabled, allows user-assisted remote attackers to execute arbitrary code via a crafted ASCII file, related to the setfilename command.
nvdosv
CVE-2004-1185P3HIGHCVSS 7.5v1.3.0v1.4.0+5 more2005-01-21
CVE-2004-1185 [HIGH] CVE-2004-1185: Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames.
nvdosv
CVE-2008-4306P3CRITICALCVSS 9.3≥ 0, < 1.6.4-132008-11-04
CVE-2008-4306 [CRITICAL] CVE-2008-4306: Buffer overflow in enscript before 1 Buffer overflow in enscript before 1.6.4 has unknown impact and attack vectors, possibly related to the font escape sequence.
osv
CVE-2008-5078P3MEDIUMCVSS 6.8≥ 0, < 1.6.4-132008-12-19
CVE-2008-5078 [MEDIUM] CVE-2008-5078: Multiple buffer overflows in the (1) recognize_eps_file function (src/psgen Multiple buffer overflows in the (1) recognize_eps_file function (src/psgen.c) and (2) tilde_subst function (src/util.c) in GNU enscript 1.6.1, and possibly earlier, might allow remote attackers to execute arbitrary code via an epsf escape sequence with a long filename.
osv
CVE-2004-1184P4MEDIUMCVSS 4.6v1.4v1.5+5 more2005-01-21
CVE-2004-1184 [MEDIUM] CVE-2004-1184: The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.
nvdosv
CVE-2004-1186P4MEDIUMCVSS 5.0v1.6.32004-12-31
CVE-2004-1186 [MEDIUM] CVE-2004-1186: Multiple buffer overflows in enscript 1.6.3 allow remote attackers or local users to cause a denial Multiple buffer overflows in enscript 1.6.3 allow remote attackers or local users to cause a denial of service (application crash).
nvdosv
CVE-2002-0044P4LOWCVSS 3.6≤ 1.6.12002-01-31
CVE-2002-0044 [LOW] CVE-2002-0044: GNU Enscript 1.6.1 and earlier allows local users to overwrite arbitrary files of the Enscript user GNU Enscript 1.6.1 and earlier allows local users to overwrite arbitrary files of the Enscript user via a symlink attack on temporary files.
nvd
Gnu Enscript vulnerabilities | cvebase