Skip to main content

Vendor archive

artifex CVEs

Beta · best-effort

257 CVEs tagged to vendor artifex30 Critical, 117 High, 108 Medium, 2 Low, 0 Unrated.

CVE-2025-71382

Published Jun 23, 2026

MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS rendering engine that allows remote attackers to cause a denial of service by supplying a…

CVSS 7.1 · High
evidence mentions
4
Buzz score
24.1
Vendor/product tagsBeta · best-effort

CVE-2026-7233

Published Apr 28, 2026

A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handl…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
37.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-40505

Published Apr 16, 2026

MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers…

CVSS 4.8 · Medium
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2026-25556

Published Feb 6, 2026

MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function…

CVSS 5.9 · Medium
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2025-55780

Published Sep 23, 2025

A null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malformed EPUB document. Specifically, the function calls fz_html…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59800

Published Sep 22, 2025

In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59799

Published Sep 22, 2025

Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdfmark_coerce_dest in devices/vector/gdevpdfm.c via a large size value.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59798

Published Sep 22, 2025

Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46206

Published Aug 4, 2025

An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted P…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48708

Published May 23, 2025

gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46646

Published Apr 26, 2025

In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954.

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27837

Published Mar 25, 2025

An issue was discovered in Artifex Ghostscript before 10.05.0. Access to arbitrary files can occur through a truncated path with invalid UTF-8 characters, for base/gp_mswin.c and…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-27836

Published Mar 25, 2025

An issue was discovered in Artifex Ghostscript before 10.05.0. The BJ10V device has a Print buffer overflow in contrib/japanese/gdev10v.c.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-27835

Published Mar 25, 2025

An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs when converting glyphs to Unicode in psi/zbfont.c.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27834

Published Mar 25, 2025

An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs via an oversized Type 4 function in a PDF document to pdf/pdf_func.c.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27833

Published Mar 25, 2025

An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs for a long TTF font name to pdf/pdf_fmap.c.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27832

Published Mar 25, 2025

An issue was discovered in Artifex Ghostscript before 10.05.0. The NPDL device has a Compression buffer overflow for contrib/japanese/gdevnpdl.c.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-27831

Published Mar 25, 2025

An issue was discovered in Artifex Ghostscript before 10.05.0. The DOCXWRITE TXTWRITE device has a text buffer overflow via long characters to devices/vector/doc_common.c.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-27830

Published Mar 25, 2025

An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs during serialization of DollarBlend in a font, for base/write_t1.c and psi/zfapi.c.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46657

Published Dec 10, 2024

Artifex Software mupdf v1.24.9 was discovered to contain a segmentation fault via the component /tools/pdfextract.c. This vulnerability allows attackers to cause a Denial of Servi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-46954

Published Nov 10, 2024

An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 257 CVEsPage 1 of 11