Skip to main content

Vendor/product archive

artifex / gpl_ghostscript CVEs

Beta · best-effort

16 CVEs tagged to artifex / gpl_ghostscript5 Critical, 8 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2018-15911

Published Aug 28, 2018

In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode operator to crash the interpreter…

CVSS 7.8 · High

CVE-2018-15910

Published Aug 27, 2018

In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the LockDistillerParams parameter to crash the interpreter or e…

CVSS 7.8 · High

CVE-2018-15909

Published Aug 27, 2018

In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScript files to crash the interpre…

CVSS 7.8 · High

CVE-2013-6629

Published Nov 19, 2013

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not c…

CVSS 5.0 · Medium

CVE-2012-4875

Published Sep 6, 2012

Heap-based buffer overflow in gdevwpr2.c in Ghostscript 9.04, when processing the OutputFile device parameter, allows user-assisted remote attackers to execute arbitrary code via…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-1628

Published May 19, 2010

Ghostscript 8.64, 8.70, and possibly other versions allows context-dependent attackers to execute arbitrary code via a PostScript file containing unlimited recursive procedure inv…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-1869

Published May 12, 2010

Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a crafted PostScript file.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1