artifex CVE Vulnerabilities & Metrics

Focus on artifex vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About artifex Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with artifex. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total artifex CVEs: 220
Earliest CVE date: 12 May 2010, 11:46 UTC
Latest CVE date: 10 Nov 2024, 22:15 UTC

Latest CVE reference: CVE-2024-46956

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 9

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -60.87%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -60.87%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical artifex CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.92

Max CVSS: 9.3

Critical CVEs (≥9): 9

CVSS Range vs. Count

Range Count
0.0-3.9 36
4.0-6.9 168
7.0-8.9 17
9.0-10.0 9

CVSS Distribution Chart

Top 5 Highest CVSS artifex CVEs

These are the five CVEs with the highest CVSS scores for artifex, sorted by severity first and recency.

All CVEs for artifex

CVE-2024-46956 artifex vulnerability CVSS: 0 10 Nov 2024, 22:15 UTC

An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.

CVE-2024-46955 artifex vulnerability CVSS: 0 10 Nov 2024, 22:15 UTC

An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space.

CVE-2024-46954 artifex vulnerability CVSS: 0 10 Nov 2024, 22:15 UTC

An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.

CVE-2024-46953 artifex vulnerability CVSS: 0 10 Nov 2024, 22:15 UTC

An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.

CVE-2024-46952 artifex vulnerability CVSS: 0 10 Nov 2024, 22:15 UTC

An issue was discovered in pdf/pdf_xref.c in Artifex Ghostscript before 10.04.0. There is a buffer overflow during handling of a PDF XRef stream (related to W array values).

CVE-2024-46951 artifex vulnerability CVSS: 0 10 Nov 2024, 21:15 UTC

An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.

CVE-2024-29509 artifex vulnerability CVSS: 0 03 Jul 2024, 18:15 UTC

Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle.

CVE-2024-29508 artifex vulnerability CVSS: 0 03 Jul 2024, 18:15 UTC

Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.

CVE-2024-29506 artifex vulnerability CVSS: 0 03 Jul 2024, 18:15 UTC

Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name.

CVE-2024-24259 artifex vulnerability CVSS: 0 05 Feb 2024, 18:15 UTC

freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function.

CVE-2024-24258 artifex vulnerability CVSS: 0 05 Feb 2024, 18:15 UTC

freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function.

CVE-2020-36773 artifex vulnerability CVSS: 0 04 Feb 2024, 18:16 UTC

Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).

CVE-2023-51107 artifex vulnerability CVSS: 0 26 Dec 2023, 15:15 UTC

A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in functon compute_color() of jquant2.c. NOTE: this is disputed by the supplier because there was not reasonable evidence to determine the existence of a vulnerability or identify the affected product.

CVE-2023-51106 artifex vulnerability CVSS: 0 26 Dec 2023, 15:15 UTC

A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in function pnm_binary_read_image() of load-pnm.c when fz_colorspace_n returns zero.

CVE-2023-51105 artifex vulnerability CVSS: 0 26 Dec 2023, 15:15 UTC

A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function bmp_decompress_rle4() of load-bmp.c.

CVE-2023-51104 artifex vulnerability CVSS: 0 26 Dec 2023, 15:15 UTC

A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function pnm_binary_read_image() of load-pnm.c when span equals zero.

CVE-2023-51103 artifex vulnerability CVSS: 0 26 Dec 2023, 15:15 UTC

A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in the function fz_new_pixmap_from_float_data() of pixmap.c.

CVE-2023-46751 artifex vulnerability CVSS: 0 06 Dec 2023, 20:15 UTC

An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10.02.0 allows remote attackers to crash the application via a dangling pointer.

CVE-2023-46361 artifex vulnerability CVSS: 0 31 Oct 2023, 06:15 UTC

Artifex Software jbig2dec v0.20 was discovered to contain a SEGV vulnerability via jbig2_error at /jbig2dec/jbig2.c.

CVE-2023-31794 artifex vulnerability CVSS: 0 31 Oct 2023, 01:15 UTC

MuPDF v1.21.1 was discovered to contain an infinite recursion in the component pdf_mark_list_push. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

CVE-2023-43115 artifex vulnerability CVSS: 0 18 Sep 2023, 08:15 UTC

In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated. NOTE: it is a documented risk that the IJS server can be specified on a gs command line (the IJS device inherently must execute a command to start the IJS server).

CVE-2023-4042 artifex vulnerability CVSS: 0 23 Aug 2023, 13:15 UTC

A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat Enterprise Linux 8.

CVE-2020-26683 artifex vulnerability CVSS: 0 22 Aug 2023, 19:16 UTC

A memory leak issue discovered in /pdf/pdf-font-add.c in Artifex Software MuPDF 1.17.0 allows attackers to obtain sensitive information.

CVE-2020-21896 artifex vulnerability CVSS: 0 22 Aug 2023, 19:16 UTC

A Use After Free vulnerability in svg_dev_text_span_as_paths_defs function in source/fitz/svg-device.c in Artifex Software MuPDF 1.16.0 allows remote attackers to cause a denial of service via opening of a crafted PDF file.

CVE-2020-21890 artifex vulnerability CVSS: 0 22 Aug 2023, 19:16 UTC

Buffer Overflow vulnerability in clj_media_size function in devices/gdevclj.c in Artifex Ghostscript 9.50 allows remote attackers to cause a denial of service or other unspecified impact(s) via opening of crafted PDF document.

CVE-2020-21710 artifex vulnerability CVSS: 0 22 Aug 2023, 19:16 UTC

A divide by zero issue discovered in eps_print_page in gdevepsn.c in Artifex Software GhostScript 9.50 allows remote attackers to cause a denial of service via opening of crafted PDF file.

CVE-2023-38560 artifex vulnerability CVSS: 0 01 Aug 2023, 17:15 UTC

An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local attacker to cause a denial of service via transforming a crafted PCL file to PDF format.

CVE-2023-38559 artifex vulnerability CVSS: 0 01 Aug 2023, 17:15 UTC

A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.

CVE-2021-33796 artifex vulnerability CVSS: 0 07 Jul 2023, 18:15 UTC

In MuJS before version 1.1.2, a use-after-free flaw in the regexp source property access may cause denial of service.

CVE-2023-36664 artifex vulnerability CVSS: 0 25 Jun 2023, 22:15 UTC

Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).

CVE-2021-33797 artifex vulnerability CVSS: 0 17 Apr 2023, 22:15 UTC

Buffer-overflow in jsdtoa.c in Artifex MuJS in versions 1.0.1 to 1.1.1. An integer overflow happens when js_strtod() reads in floating point exponent, which leads to a buffer overflow in the pointer *d.

CVE-2023-28879 artifex vulnerability CVSS: 0 31 Mar 2023, 17:15 UTC

In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.

CVE-2022-44789 artifex vulnerability CVSS: 0 23 Nov 2022, 21:15 UTC

A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file.

CVE-2021-4216 artifex vulnerability CVSS: 0 26 Aug 2022, 16:15 UTC

A Floating point exception (division-by-zero) flaw was found in Mupdf for zero width pages in muraster.c. It is fixed in Mupdf-1.20.0-rc1 upstream.

CVE-2020-27792 artifex vulnerability CVSS: 0 19 Aug 2022, 23:15 UTC

A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.

CVE-2022-2085 artifex vulnerability CVSS: 4.3 16 Jun 2022, 18:15 UTC

A NULL pointer dereference vulnerability was found in Ghostscript, which occurs when it tries to render a large number of bits in memory. When allocating a buffer device, it relies on an init_device_procs defined for the device that uses it as a prototype that depends upon the number of bits per pixel. For bpp > 64, mem_x_device is used and does not have an init_device_procs defined. This flaw allows an attacker to parse a large number of bits (more than 64 bits per pixel), which triggers a NULL pointer dereference flaw, causing an application to crash.

CVE-2022-30975 artifex vulnerability CVSS: 4.3 18 May 2022, 11:15 UTC

In Artifex MuJS through 1.2.0, jsP_dumpsyntax in jsdump.c has a NULL pointer dereference, as demonstrated by mujs-pp.

CVE-2022-30974 artifex vulnerability CVSS: 4.3 18 May 2022, 11:15 UTC

compile in regexp.c in Artifex MuJS through 1.2.0 results in stack consumption because of unlimited recursion, a different issue than CVE-2019-11413.

CVE-2019-25059 artifex vulnerability CVSS: 6.8 25 Apr 2022, 04:15 UTC

Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.

CVE-2022-1350 artifex vulnerability CVSS: 6.8 14 Apr 2022, 07:15 UTC

A vulnerability classified as problematic was found in GhostPCL 9.55.0. This vulnerability affects the function chunk_free_object of the file gsmchunk.c. The manipulation with a malicious file leads to a memory corruption. The attack can be initiated remotely but requires user interaction. The exploit has been disclosed to the public as a POC and may be used. It is recommended to apply the patches to fix this issue.

CVE-2021-3781 artifex vulnerability CVSS: 9.3 16 Feb 2022, 19:15 UTC

A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript interpreter. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVE-2021-45005 artifex vulnerability CVSS: 7.5 14 Feb 2022, 22:15 UTC

Artifex MuJS v1.1.3 was discovered to contain a heap buffer overflow which is caused by conflicting JumpList of nested try/finally statements.

CVE-2021-45949 artifex vulnerability CVSS: 4.3 01 Jan 2022, 00:15 UTC

Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).

CVE-2021-45944 artifex vulnerability CVSS: 4.3 01 Jan 2022, 00:15 UTC

Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp).

CVE-2021-37220 artifex vulnerability CVSS: 4.3 21 Jul 2021, 22:15 UTC

MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.

CVE-2020-19609 artifex vulnerability CVSS: 4.3 21 Jul 2021, 15:15 UTC

Artifex MuPDF before 1.18.0 has a heap based buffer over-write in tiff_expand_colormap() function when parsing TIFF files allowing attackers to cause a denial of service.

CVE-2020-22886 artifex vulnerability CVSS: 5.0 13 Jul 2021, 15:15 UTC

Buffer overflow vulnerability in function jsG_markobject in jsgc.c in mujs before 1.0.8, allows remote attackers to cause a denial of service.

CVE-2020-22885 artifex vulnerability CVSS: 5.0 13 Jul 2021, 15:15 UTC

Buffer overflow vulnerability in mujs before 1.0.8 due to recursion in the GC scanning phase, allows remote attackers to cause a denial of service.

CVE-2021-3407 artifex vulnerability CVSS: 4.3 23 Feb 2021, 23:15 UTC

A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences.

CVE-2020-16600 artifex vulnerability CVSS: 6.8 09 Dec 2020, 21:15 UTC

A Use After Free vulnerability exists in Artifex Software, Inc. MuPDF library 1.17.0-rc1 and earlier when a valid page was followed by a page with invalid pixmap dimensions, causing bander - a static - to point to previously freed memory instead of a newband_writer.

CVE-2020-26519 artifex vulnerability CVSS: 4.3 02 Oct 2020, 06:15 UTC

Artifex MuPDF before 1.18.0 has a heap based buffer over-write when parsing JBIG2 files allowing attackers to cause a denial of service.

CVE-2020-14373 artifex vulnerability CVSS: 2.1 03 Sep 2020, 18:15 UTC

A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25. A local attacker could supply a specially crafted PDF file to cause a denial of service.

CVE-2020-24343 artifex vulnerability CVSS: 6.8 13 Aug 2020, 19:15 UTC

Artifex MuJS through 1.0.7 has a use-after-free in jsrun.c because of unconditional marking in jsgc.c.

CVE-2020-17538 artifex vulnerability CVSS: 4.3 13 Aug 2020, 03:15 UTC

A buffer overflow vulnerability in GetNumSameData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-16310 artifex vulnerability CVSS: 4.3 13 Aug 2020, 03:15 UTC

A division by zero vulnerability in dot24_print_page() in devices/gdevdm24.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-16309 artifex vulnerability CVSS: 4.3 13 Aug 2020, 03:15 UTC

A buffer overflow vulnerability in lxm5700m_print_page() in devices/gdevlxm.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted eps file. This is fixed in v9.51.

CVE-2020-16308 artifex vulnerability CVSS: 4.3 13 Aug 2020, 03:15 UTC

A buffer overflow vulnerability in p_print_image() in devices/gdevcdj.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-16307 artifex vulnerability CVSS: 4.3 13 Aug 2020, 03:15 UTC

A null pointer dereference vulnerability in devices/vector/gdevtxtw.c and psi/zbfont.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fixed in v9.51.

CVE-2020-16306 artifex vulnerability CVSS: 4.3 13 Aug 2020, 03:15 UTC

A null pointer dereference vulnerability in devices/gdevtsep.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fixed in v9.51.

CVE-2020-16305 artifex vulnerability CVSS: 4.3 13 Aug 2020, 03:15 UTC

A buffer overflow vulnerability in pcx_write_rle() in contrib/japanese/gdev10v.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-16304 artifex vulnerability CVSS: 4.3 13 Aug 2020, 03:15 UTC

A buffer overflow vulnerability in image_render_color_thresh() in base/gxicolor.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to escalate privileges via a crafted eps file. This is fixed in v9.51.

CVE-2020-16303 artifex vulnerability CVSS: 6.8 13 Aug 2020, 03:15 UTC

A use-after-free vulnerability in xps_finish_image_path() in devices/vector/gdevxps.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51.

CVE-2020-16302 artifex vulnerability CVSS: 4.3 13 Aug 2020, 03:15 UTC

A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51.

CVE-2020-16301 artifex vulnerability CVSS: 4.3 13 Aug 2020, 03:15 UTC

A buffer overflow vulnerability in okiibm_print_page1() in devices/gdevokii.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-16300 artifex vulnerability CVSS: 4.3 13 Aug 2020, 03:15 UTC

A buffer overflow vulnerability in tiff12_print_page() in devices/gdevtfnx.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-16299 artifex vulnerability CVSS: 4.3 13 Aug 2020, 03:15 UTC

A Division by Zero vulnerability in bj10v_print_page() in contrib/japanese/gdev10v.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-16298 artifex vulnerability CVSS: 4.3 13 Aug 2020, 03:15 UTC

A buffer overflow vulnerability in mj_color_correct() in contrib/japanese/gdevmjc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-16297 artifex vulnerability CVSS: 4.3 13 Aug 2020, 03:15 UTC

A buffer overflow vulnerability in FloydSteinbergDitheringC() in contrib/gdevbjca.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-16296 artifex vulnerability CVSS: 4.3 13 Aug 2020, 03:15 UTC

A buffer overflow vulnerability in GetNumWrongData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-16295 artifex vulnerability CVSS: 4.3 13 Aug 2020, 03:15 UTC

A null pointer dereference vulnerability in clj_media_size() in devices/gdevclj.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-16294 artifex vulnerability CVSS: 4.3 13 Aug 2020, 03:15 UTC

A buffer overflow vulnerability in epsc_print_page() in devices/gdevepsc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-16293 artifex vulnerability CVSS: 4.3 13 Aug 2020, 03:15 UTC

A null pointer dereference vulnerability in compose_group_nonknockout_nonblend_isolated_allmask_common() in base/gxblend.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-16292 artifex vulnerability CVSS: 4.3 13 Aug 2020, 03:15 UTC

A buffer overflow vulnerability in mj_raster_cmd() in contrib/japanese/gdevmjc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-16291 artifex vulnerability CVSS: 4.3 13 Aug 2020, 03:15 UTC

A buffer overflow vulnerability in contrib/gdevdj9.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-16290 artifex vulnerability CVSS: 4.3 13 Aug 2020, 03:15 UTC

A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-16289 artifex vulnerability CVSS: 4.3 13 Aug 2020, 03:15 UTC

A buffer overflow vulnerability in cif_print_page() in devices/gdevcif.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-16288 artifex vulnerability CVSS: 4.3 13 Aug 2020, 03:15 UTC

A buffer overflow vulnerability in pj_common_print_page() in devices/gdevpjet.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-16287 artifex vulnerability CVSS: 4.3 13 Aug 2020, 03:15 UTC

A buffer overflow vulnerability in lprn_is_black() in contrib/lips4/gdevlprn.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-15900 artifex vulnerability CVSS: 7.5 28 Jul 2020, 16:15 UTC

A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and could underflow to max uint32_t. This was fixed in commit 5d499272b95a6b890a1397e11d20937de000d31b.

CVE-2020-12268 artifex vulnerability CVSS: 7.5 27 Apr 2020, 02:15 UTC

jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow.

CVE-2012-5340 artifex vulnerability CVSS: 6.8 23 Jan 2020, 22:15 UTC

SumatraPDF 2.1.1/MuPDF 1.0 allows remote attackers to cause an Integer Overflow in the lex_number() function via a corrupt PDF file.

CVE-2019-14812 artifex vulnerability CVSS: 6.8 27 Nov 2019, 14:15 UTC

A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.

CVE-2019-10216 artifex vulnerability CVSS: 6.8 27 Nov 2019, 13:15 UTC

In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and access files outside of restricted areas.

CVE-2019-14869 artifex vulnerability CVSS: 6.8 15 Nov 2019, 12:15 UTC

A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges within the Ghostscript and access files outside of restricted areas or execute commands.

CVE-2019-14813 artifex vulnerability CVSS: 7.5 06 Sep 2019, 14:15 UTC

A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.

CVE-2019-14817 artifex vulnerability CVSS: 6.8 03 Sep 2019, 16:15 UTC

A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.

CVE-2019-14811 artifex vulnerability CVSS: 6.8 03 Sep 2019, 16:15 UTC

A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.

CVE-2019-14975 artifex vulnerability CVSS: 5.8 14 Aug 2019, 13:15 UTC

Artifex MuPDF before 1.16.0 has a heap-based buffer over-read in fz_chartorune in fitz/string.c because pdf/pdf-op-filter.c does not check for a missing string.

CVE-2019-13290 artifex vulnerability CVSS: 6.8 04 Jul 2019, 22:15 UTC

Artifex MuPDF 1.15.0 has a heap-based buffer overflow in fz_append_display_node located at fitz/list-device.c, allowing remote attackers to execute arbitrary code via a crafted PDF file. This occurs with a large BDC property name that overflows the allocated size of a display list node.

CVE-2019-7321 artifex vulnerability CVSS: 7.5 13 Jun 2019, 18:29 UTC

Usage of an uninitialized variable in the function fz_load_jpeg in Artifex MuPDF 1.14 can result in a heap overflow vulnerability that allows an attacker to execute arbitrary code.

CVE-2019-12798 artifex vulnerability CVSS: 7.5 13 Jun 2019, 17:29 UTC

An issue was discovered in Artifex MuJS 1.0.5. regcompx in regexp.c does not restrict regular expression program size, leading to an overflow of the parsed syntax list size.

CVE-2017-15652 artifex vulnerability CVSS: 4.3 23 May 2019, 15:29 UTC

Artifex Ghostscript 9.22 is affected by: Obtain Information. The impact is: obtain sensitive information. The component is: affected source code file, affected function, affected executable, affected libga (imagemagick used that). The attack vector is: Someone must open a postscript file though ghostscript. Because of imagemagick also use libga, so it was affected as well.

CVE-2019-3839 artifex vulnerability CVSS: 6.8 16 May 2019, 19:29 UTC

It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.

CVE-2019-11413 artifex vulnerability CVSS: 5.0 22 Apr 2019, 11:29 UTC

An issue was discovered in Artifex MuJS 1.0.5. It has unlimited recursion because the match function in regexp.c lacks a depth check.

CVE-2019-11412 artifex vulnerability CVSS: 5.0 22 Apr 2019, 11:29 UTC

An issue was discovered in Artifex MuJS 1.0.5. jscompile.c can cause a denial of service (invalid stack-frame jump) because it lacks an ENDTRY opcode call.

CVE-2019-11411 artifex vulnerability CVSS: 7.5 22 Apr 2019, 11:29 UTC

An issue was discovered in Artifex MuJS 1.0.5. The Number#toFixed() and numtostr implementations in jsnumber.c have a stack-based buffer overflow.

CVE-2019-3838 artifex vulnerability CVSS: 4.3 25 Mar 2019, 19:29 UTC

It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.

CVE-2019-3835 artifex vulnerability CVSS: 4.3 25 Mar 2019, 19:29 UTC

It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.

CVE-2019-6116 artifex vulnerability CVSS: 6.8 21 Mar 2019, 16:01 UTC

In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.

CVE-2019-6131 artifex vulnerability CVSS: 4.3 11 Jan 2019, 05:29 UTC

svg-run.c in Artifex MuPDF 1.14.0 has infinite recursion with stack consumption in svg_run_use_symbol, svg_run_element, and svg_run_use, as demonstrated by mutool.

CVE-2019-6130 artifex vulnerability CVSS: 4.3 11 Jan 2019, 05:29 UTC

Artifex MuPDF 1.14.0 has a SEGV in the function fz_load_page of the fitz/document.c file, as demonstrated by mutool. This is related to page-number mishandling in cbz/mucbz.c, cbz/muimg.c, and svg/svg-doc.c.

CVE-2018-19478 artifex vulnerability CVSS: 4.3 02 Jan 2019, 18:29 UTC

In Artifex Ghostscript before 9.26, a carefully crafted PDF file can trigger an extremely long running computation when parsing the file.

CVE-2018-19134 artifex vulnerability CVSS: 6.8 20 Dec 2018, 23:29 UTC

In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscript process. This is a type confusion issue because of failure to check whether the Implementation of a pattern dictionary was a structure type.

CVE-2018-19882 artifex vulnerability CVSS: 4.3 06 Dec 2018, 00:29 UTC

In Artifex MuPDF 1.14.0, the svg_run_image function in svg/svg-run.c allows remote attackers to cause a denial of service (href_att NULL pointer dereference and application crash) via a crafted svg file, as demonstrated by mupdf-gl.

CVE-2018-19881 artifex vulnerability CVSS: 4.3 06 Dec 2018, 00:29 UTC

In Artifex MuPDF 1.14.0, svg/svg-run.c allows remote attackers to cause a denial of service (recursive calls followed by a fitz/xml.c fz_xml_att crash from excessive stack consumption) via a crafted svg file, as demonstrated by mupdf-gl.

CVE-2018-16863 artifex vulnerability CVSS: 9.3 03 Dec 2018, 17:29 UTC

It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSAFER protection to, for example, execute arbitrary shell commands via a specially crafted PostScript document. This only affects ghostscript 9.07 as shipped with Red Hat Enterprise Linux 7.

CVE-2018-19777 artifex vulnerability CVSS: 4.3 30 Nov 2018, 10:29 UTC

In Artifex MuPDF 1.14.0, there is an infinite loop in the function svg_dev_end_tile in fitz/svg-device.c, as demonstrated by mutool.

CVE-2018-19477 artifex vulnerability CVSS: 6.8 23 Nov 2018, 05:29 UTC

psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a JBIG2Decode type confusion.

CVE-2018-19476 artifex vulnerability CVSS: 6.8 23 Nov 2018, 05:29 UTC

psi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a setcolorspace type confusion.

CVE-2018-19475 artifex vulnerability CVSS: 6.8 23 Nov 2018, 05:29 UTC

psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same.

CVE-2018-19409 artifex vulnerability CVSS: 7.5 21 Nov 2018, 16:29 UTC

An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device is used.

CVE-2018-18662 artifex vulnerability CVSS: 4.3 26 Oct 2018, 14:29 UTC

There is an out-of-bounds read in fz_run_t3_glyph in fitz/font.c in Artifex MuPDF 1.14.0, as demonstrated by mutool.

CVE-2018-18284 artifex vulnerability CVSS: 6.8 19 Oct 2018, 22:29 UTC

Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator.

CVE-2018-18073 artifex vulnerability CVSS: 4.3 15 Oct 2018, 16:29 UTC

Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure of system operators in the saved execution stack in an error object.

CVE-2018-17961 artifex vulnerability CVSS: 6.8 15 Oct 2018, 16:29 UTC

Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue exists because of an incomplete fix for CVE-2018-17183.

CVE-2018-17183 artifex vulnerability CVSS: 6.8 19 Sep 2018, 15:29 UTC

Artifex Ghostscript before 9.25 allowed a user-writable error exception table, which could be used by remote attackers able to supply crafted PostScript to potentially overwrite or replace error handlers to inject code.

CVE-2018-16802 artifex vulnerability CVSS: 6.8 10 Sep 2018, 16:29 UTC

An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" checking when running out of stack during exception handling could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction. This is due to an incomplete fix for CVE-2018-16509.

CVE-2018-16648 artifex vulnerability CVSS: 4.3 06 Sep 2018, 23:29 UTC

In Artifex MuPDF 1.13.0, the fz_append_byte function in fitz/buffer.c allows remote attackers to cause a denial of service (segmentation fault) via a crafted pdf file. This is caused by a pdf/pdf-device.c pdf_dev_alpha array-index underflow.

CVE-2018-16647 artifex vulnerability CVSS: 4.3 06 Sep 2018, 23:29 UTC

In Artifex MuPDF 1.13.0, the pdf_get_xref_entry function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation fault in fz_write_data in fitz/output.c) via a crafted pdf file.

CVE-2018-16585 artifex vulnerability CVSS: 6.8 06 Sep 2018, 14:29 UTC

An issue was discovered in Artifex Ghostscript before 9.24. The .setdistillerkeys PostScript command is accepted even though it is not intended for use during document processing (e.g., after the startup phase). This leads to memory corruption, allowing remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact. Note: A reputable source believes that the CVE is potentially a duplicate of CVE-2018-15910 as explained in Red Hat bugzilla (https://bugzilla.redhat.com/show_bug.cgi?id=1626193)

CVE-2018-16543 artifex vulnerability CVSS: 6.8 05 Sep 2018, 18:29 UTC

In Artifex Ghostscript before 9.24, gssetresolution and gsgetresolution allow attackers to have an unspecified impact.

CVE-2018-16542 artifex vulnerability CVSS: 4.3 05 Sep 2018, 18:29 UTC

In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use insufficient interpreter stack-size checking during error handling to crash the interpreter.

CVE-2018-16541 artifex vulnerability CVSS: 4.3 05 Sep 2018, 18:29 UTC

In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect free logic in pagedevice replacement to crash the interpreter.

CVE-2018-16540 artifex vulnerability CVSS: 6.8 05 Sep 2018, 18:29 UTC

In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified other impact.

CVE-2018-16539 artifex vulnerability CVSS: 4.3 05 Sep 2018, 18:29 UTC

In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect access checking in temp file handling to disclose contents of files on the system otherwise not readable.

CVE-2018-16513 artifex vulnerability CVSS: 6.8 05 Sep 2018, 13:29 UTC

In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the setcolor function to crash the interpreter or possibly have unspecified other impact.

CVE-2018-16511 artifex vulnerability CVSS: 6.8 05 Sep 2018, 06:29 UTC

An issue was discovered in Artifex Ghostscript before 9.24. A type confusion in "ztype" could be used by remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact.

CVE-2018-16510 artifex vulnerability CVSS: 6.8 05 Sep 2018, 06:29 UTC

An issue was discovered in Artifex Ghostscript before 9.24. Incorrect exec stack handling in the "CS" and "SC" PDF primitives could be used by remote attackers able to supply crafted PDFs to crash the interpreter or possibly have unspecified other impact.

CVE-2018-16509 artifex vulnerability CVSS: 9.3 05 Sep 2018, 06:29 UTC

An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction.

CVE-2018-15911 artifex vulnerability CVSS: 6.8 28 Aug 2018, 04:29 UTC

In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode operator to crash the interpreter or potentially execute code.

CVE-2018-15910 artifex vulnerability CVSS: 6.8 27 Aug 2018, 17:29 UTC

In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the LockDistillerParams parameter to crash the interpreter or execute code.

CVE-2018-15909 artifex vulnerability CVSS: 6.8 27 Aug 2018, 17:29 UTC

In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScript files to crash the interpreter or potentially execute code.

CVE-2018-15908 artifex vulnerability CVSS: 6.8 27 Aug 2018, 17:29 UTC

In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript files to bypass .tempfile restrictions and write files.

CVE-2018-11645 artifex vulnerability CVSS: 5.0 01 Jun 2018, 12:29 UTC

psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a similar issue to CVE-2016-7977.

CVE-2018-1000040 artifex vulnerability CVSS: 4.3 24 May 2018, 13:29 UTC

In Artifex MuPDF 1.12.0 and earlier, multiple use of uninitialized value bugs in the PDF parser could allow an attacker to cause a denial of service (crash) or influence program flow via a crafted file.

CVE-2018-1000039 artifex vulnerability CVSS: 6.8 24 May 2018, 13:29 UTC

In Artifex MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PDF parser could allow an attacker to execute arbitrary code, read memory, or cause a denial of service via a crafted file.

CVE-2018-1000038 artifex vulnerability CVSS: 6.8 24 May 2018, 13:29 UTC

In Artifex MuPDF 1.12.0 and earlier, a stack buffer overflow in function pdf_lookup_cmap_full in pdf/pdf-cmap.c could allow an attacker to execute arbitrary code via a crafted file.

CVE-2018-1000037 artifex vulnerability CVSS: 4.3 24 May 2018, 13:29 UTC

In Artifex MuPDF 1.12.0 and earlier, multiple reachable assertions in the PDF parser allow an attacker to cause a denial of service (assert crash) via a crafted file.

CVE-2018-1000036 artifex vulnerability CVSS: 4.3 24 May 2018, 13:29 UTC

In Artifex MuPDF 1.12.0 and earlier, multiple memory leaks in the PDF parser allow an attacker to cause a denial of service (memory leak) via a crafted file.

CVE-2016-8729 artifex vulnerability CVSS: 6.8 24 Apr 2018, 19:29 UTC

An exploitable memory corruption vulnerability exists in the JBIG2 parser of Artifex MuPDF 1.9. A specially crafted PDF can cause a negative number to be passed to a memset resulting in memory corruption and potential code execution. An attacker can specially craft a PDF and send to the victim to trigger this vulnerability.

CVE-2016-8728 artifex vulnerability CVSS: 6.8 24 Apr 2018, 19:29 UTC

An exploitable heap out of bounds write vulnerability exists in the Fitz graphical library part of the MuPDF renderer. A specially crafted PDF file can cause a out of bounds write resulting in heap metadata and sensitive process memory corruption leading to potential code execution. Victim needs to open the specially crafted file in a vulnerable reader in order to trigger this vulnerability.

CVE-2016-9601 artifex vulnerability CVSS: 4.3 24 Apr 2018, 01:29 UTC

ghostscript before version 9.21 is vulnerable to a heap based buffer overflow that was found in the ghostscript jbig2_decode_gray_scale_image function which is used to decode halftone segments in a JBIG2 image. A document (PostScript or PDF) with an embedded, specially crafted, jbig2 image could trigger a segmentation fault in ghostscript.

CVE-2018-10289 artifex vulnerability CVSS: 4.3 22 Apr 2018, 05:29 UTC

In MuPDF 1.13.0, there is an infinite loop in the fz_skip_space function of the pdf/pdf-xref.c file. A remote adversary could leverage this vulnerability to cause a denial of service via a crafted pdf file.

CVE-2018-10194 artifex vulnerability CVSS: 6.8 18 Apr 2018, 21:29 UTC

The set_text_distance function in devices/vector/gdevpdts.c in the pdfwrite component in Artifex Ghostscript through 9.22 does not prevent overflows in text-positioning calculation, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.

CVE-2018-1000051 artifex vulnerability CVSS: 6.8 09 Feb 2018, 23:29 UTC

Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_key_storable that can result in DOS / Possible code execution. This attack appear to be exploitable via Victim opens a specially crafted PDF.

CVE-2018-6544 artifex vulnerability CVSS: 4.3 02 Feb 2018, 09:29 UTC

pdf_load_obj_stm in pdf/pdf-xref.c in Artifex MuPDF 1.12.0 could reference the object stream recursively and therefore run out of error stack, which allows remote attackers to cause a denial of service via a crafted PDF document.

CVE-2018-6192 artifex vulnerability CVSS: 4.3 24 Jan 2018, 21:29 UTC

In Artifex MuPDF 1.12.0, the pdf_read_new_xref function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation violation and application crash) via a crafted pdf file.

CVE-2018-6191 artifex vulnerability CVSS: 4.3 24 Jan 2018, 21:29 UTC

The js_strtod function in jsdtoa.c in Artifex MuJS through 1.0.2 has an integer overflow because of incorrect exponent validation.

CVE-2018-5759 artifex vulnerability CVSS: 4.3 24 Jan 2018, 21:29 UTC

jsparse.c in Artifex MuJS through 1.0.2 does not properly maintain the AST depth for binary expressions, which allows remote attackers to cause a denial of service (excessive recursion) via a crafted file.

CVE-2018-6187 artifex vulnerability CVSS: 4.3 24 Jan 2018, 10:29 UTC

In Artifex MuPDF 1.12.0, there is a heap-based buffer overflow vulnerability in the do_pdf_save_document function in the pdf/pdf-write.c file. Remote attackers could leverage the vulnerability to cause a denial of service via a crafted pdf file.

CVE-2017-17858 artifex vulnerability CVSS: 6.8 22 Jan 2018, 15:29 UTC

Heap-based buffer overflow in the ensure_solid_xref function in pdf/pdf-xref.c in Artifex MuPDF 1.12.0 allows a remote attacker to potentially execute arbitrary code via a crafted PDF file, because xref subsection object numbers are unrestricted.

CVE-2018-5686 artifex vulnerability CVSS: 4.3 14 Jan 2018, 02:29 UTC

In MuPDF 1.12.0, there is an infinite loop vulnerability and application hang in the pdf_parse_array function (pdf/pdf-parse.c) because EOF is not considered. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted pdf file.

CVE-2017-17866 artifex vulnerability CVSS: 6.8 27 Dec 2017, 17:08 UTC

pdf/pdf-write.c in Artifex MuPDF before 1.12.0 mishandles certain length changes when a repair operation occurs during a clean operation, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted PDF document.

CVE-2017-15587 artifex vulnerability CVSS: 6.8 18 Oct 2017, 08:29 UTC

An integer overflow was discovered in pdf_read_new_xref_section in pdf/pdf-xref.c in Artifex MuPDF 1.11.

CVE-2017-15369 artifex vulnerability CVSS: 6.8 16 Oct 2017, 01:29 UTC

The build_filter_chain function in pdf/pdf-stream.c in Artifex MuPDF before 2017-09-25 mishandles a certain case where a variable may reside in a register, which allows remote attackers to cause a denial of service (Fitz fz_drop_imp use-after-free and application crash) or possibly have unspecified other impact via a crafted PDF document.

CVE-2017-14947 artifex vulnerability CVSS: 6.8 30 Sep 2017, 01:29 UTC

Artifex GSView 6.0 Beta on Windows allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "Read Access Violation on Block Data Move starting at mupdfnet64!mIncrementalSaveFile+0x0000000000193359."

CVE-2017-14946 artifex vulnerability CVSS: 6.8 30 Sep 2017, 01:29 UTC

Artifex GSView 6.0 Beta on Windows allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at mupdfnet64!mIncrementalSaveFile+0x000000000000344e."

CVE-2017-14945 artifex vulnerability CVSS: 6.8 30 Sep 2017, 01:29 UTC

Artifex GSView 6.0 Beta on Windows allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Possible Stack Corruption starting at KERNELBASE!RaiseException+0x0000000000000068."

CVE-2017-14687 artifex vulnerability CVSS: 6.8 22 Sep 2017, 06:29 UTC

Artifex MuPDF 1.11 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to "Data from Faulting Address controls Branch Selection starting at mupdf+0x000000000016cb4f" on Windows. This occurs because of mishandling of XML tag name comparisons.

CVE-2017-14686 artifex vulnerability CVSS: 6.8 22 Sep 2017, 06:29 UTC

Artifex MuPDF 1.11 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "User Mode Write AV near NULL starting at wow64!Wow64NotifyDebugger+0x000000000000001d" on Windows. This occurs because read_zip_dir_imp in fitz/unzip.c does not check whether size fields in a ZIP entry are negative numbers.

CVE-2017-14685 artifex vulnerability CVSS: 6.8 22 Sep 2017, 06:29 UTC

Artifex MuPDF 1.11 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to "Data from Faulting Address controls Branch Selection starting at mupdf+0x000000000016aa61" on Windows. This occurs because xps_load_links_in_glyphs in xps/xps-link.c does not verify that an xps font could be loaded.

CVE-2016-7976 artifex vulnerability CVSS: 6.8 07 Aug 2017, 20:29 UTC

The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.

CVE-2017-11714 artifex vulnerability CVSS: 6.8 28 Jul 2017, 05:29 UTC

psi/ztoken.c in Artifex Ghostscript 9.21 mishandles references to the scanner state structure, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PostScript document, related to an out-of-bounds read in the igc_reloc_struct_ptr function in psi/igc.c.

CVE-2017-9835 artifex vulnerability CVSS: 6.8 26 Jul 2017, 19:29 UTC

The gs_alloc_ref_array function in psi/ialloc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PostScript document. This is related to a lack of an integer overflow check in base/gsalloc.c.

CVE-2017-9740 artifex vulnerability CVSS: 6.8 26 Jul 2017, 19:29 UTC

The xps_decode_font_char_imp function in xps/xpsfont.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document.

CVE-2017-9739 artifex vulnerability CVSS: 6.8 26 Jul 2017, 19:29 UTC

The Ins_JMPR function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document.

CVE-2017-9727 artifex vulnerability CVSS: 6.8 26 Jul 2017, 19:29 UTC

The gx_ttfReader__Read function in base/gxttfb.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document.

CVE-2017-9726 artifex vulnerability CVSS: 6.8 26 Jul 2017, 19:29 UTC

The Ins_MDRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document.

CVE-2017-9620 artifex vulnerability CVSS: 6.8 26 Jul 2017, 19:29 UTC

The xps_select_font_encoding function in xps/xpsfont.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document, related to the xps_encode_font_char_imp function.

CVE-2017-9619 artifex vulnerability CVSS: 6.8 26 Jul 2017, 19:29 UTC

The xps_true_callback_glyph_name function in xps/xpsttf.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (Segmentation Violation and application crash) via a crafted file.

CVE-2017-9618 artifex vulnerability CVSS: 6.8 26 Jul 2017, 19:29 UTC

The xps_load_sfnt_name function in xps/xpsfont.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted document.

CVE-2017-9612 artifex vulnerability CVSS: 6.8 26 Jul 2017, 19:29 UTC

The Ins_IP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact via a crafted document.

CVE-2017-9611 artifex vulnerability CVSS: 6.8 26 Jul 2017, 19:29 UTC

The Ins_MIRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document.

CVE-2017-9610 artifex vulnerability CVSS: 6.8 26 Jul 2017, 19:29 UTC

The xps_load_sfnt_name function in xps/xpsfont.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document.

CVE-2017-9216 artifex vulnerability CVSS: 4.3 24 May 2017, 05:29 UTC

libjbig2dec.a in Artifex jbig2dec 0.13, as used in MuPDF and Ghostscript, has a NULL pointer dereference in the jbig2_huffman_get function in jbig2_huffman.c. For example, the jbig2dec utility will crash (segmentation fault) when parsing an invalid file.

CVE-2016-7979 artifex vulnerability CVSS: 7.5 23 May 2017, 04:29 UTC

Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code by leveraging type confusion in .initialize_dsc_parser.

CVE-2016-7978 artifex vulnerability CVSS: 7.5 23 May 2017, 04:29 UTC

Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors related to a reference leak in .setdevice.

CVE-2016-7977 artifex vulnerability CVSS: 4.3 23 May 2017, 04:29 UTC

Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use of the .libfile operator in a crafted postscript document.

CVE-2017-8908 artifex vulnerability CVSS: 4.3 12 May 2017, 07:29 UTC

The mark_line_tr function in gxscanc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PostScript document.

CVE-2017-8291 artifex vulnerability CVSS: 6.8 27 Apr 2017, 01:59 UTC

Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs program, as exploited in the wild in April 2017.

CVE-2017-7976 artifex vulnerability CVSS: 5.8 19 Apr 2017, 17:59 UTC

Artifex jbig2dec 0.13 allows out-of-bounds writes and reads because of an integer overflow in the jbig2_image_compose function in jbig2_image.c during operations on a crafted .jb2 file, leading to a denial of service (application crash) or disclosure of sensitive information from process memory.

CVE-2017-7975 artifex vulnerability CVSS: 6.8 19 Apr 2017, 16:59 UTC

Artifex jbig2dec 0.13, as used in Ghostscript, allows out-of-bounds writes because of an integer overflow in the jbig2_build_huffman_table function in jbig2_huffman.c during operations on a crafted JBIG2 file, leading to a denial of service (application crash) or possibly execution of arbitrary code.

CVE-2017-7948 artifex vulnerability CVSS: 6.8 19 Apr 2017, 14:59 UTC

Integer overflow in the mark_curve function in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via a crafted PostScript document.

CVE-2017-7885 artifex vulnerability CVSS: 5.8 17 Apr 2017, 00:59 UTC

Artifex jbig2dec 0.13 has a heap-based buffer over-read leading to denial of service (application crash) or disclosure of sensitive information from process memory, because of an integer overflow in the jbig2_decode_symbol_dict function in jbig2_symbol_dict.c in libjbig2dec.a during operation on a crafted .jb2 file.

CVE-2016-8602 artifex vulnerability CVSS: 6.8 14 Apr 2017, 18:59 UTC

The .sethalftone5 function in psi/zht2.c in Ghostscript before 9.21 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Postscript document that calls .sethalftone5 with an empty operand stack.

CVE-2016-10317 artifex vulnerability CVSS: 6.8 03 Apr 2017, 20:59 UTC

The fill_threshhold_buffer function in base/gxht_thresh.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PostScript document.

CVE-2017-5951 artifex vulnerability CVSS: 4.3 03 Apr 2017, 05:59 UTC

The mem_get_bits_rectangle function in base/gdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.

CVE-2016-10221 artifex vulnerability CVSS: 4.3 03 Apr 2017, 05:59 UTC

The count_entries function in pdf-layer.c in Artifex Software, Inc. MuPDF 1.10a allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted PDF document.

CVE-2016-10220 artifex vulnerability CVSS: 4.3 03 Apr 2017, 05:59 UTC

The gs_makewordimagedevice function in base/gsdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file that is mishandled in the PDF Transparency module.

CVE-2016-10219 artifex vulnerability CVSS: 4.3 03 Apr 2017, 05:59 UTC

The intersect function in base/gxfill.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.

CVE-2016-10218 artifex vulnerability CVSS: 4.3 03 Apr 2017, 05:59 UTC

The pdf14_pop_transparency_group function in base/gdevp14.c in the PDF Transparency module in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.

CVE-2016-10217 artifex vulnerability CVSS: 4.3 03 Apr 2017, 05:59 UTC

The pdf14_open function in base/gdevp14.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted file that is mishandled in the color management module.

CVE-2017-7264 artifex vulnerability CVSS: 6.8 26 Mar 2017, 05:59 UTC

Use-after-free vulnerability in the fz_subsample_pixmap function in fitz/pixmap.c in Artifex MuPDF 1.10a allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted document.

CVE-2016-10133 artifex vulnerability CVSS: 7.5 24 Mar 2017, 15:59 UTC

Heap-based buffer overflow in the js_stackoverflow function in jsrun.c in Artifex Software, Inc. MuJS allows attackers to have unspecified impact by leveraging an error when dropping extra arguments to lightweight functions.

CVE-2016-10132 artifex vulnerability CVSS: 5.0 24 Mar 2017, 15:59 UTC

regexp.c in Artifex Software, Inc. MuJS allows attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to regular expression compilation.

CVE-2017-7207 artifex vulnerability CVSS: 4.3 21 Mar 2017, 06:59 UTC

The mem_get_bits_rectangle function in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted PostScript document.

CVE-2016-10247 artifex vulnerability CVSS: 4.3 16 Mar 2017, 14:59 UTC

Buffer overflow in the my_getline function in jstest_main.c in Mujstest in Artifex Software, Inc. MuPDF before 1.10 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file.

CVE-2016-10246 artifex vulnerability CVSS: 4.3 16 Mar 2017, 14:59 UTC

Buffer overflow in the main function in jstest_main.c in Mujstest in Artifex Software, Inc. MuPDF before 1.10 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file.

CVE-2017-6060 artifex vulnerability CVSS: 6.8 15 Mar 2017, 14:59 UTC

Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, Inc. MuPDF 1.10a allows remote attackers to have unspecified impact via a crafted image.

CVE-2013-5653 artifex vulnerability CVSS: 4.3 07 Mar 2017, 15:59 UTC

The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER" argument, which allows remote attackers to read data via a crafted postscript file.

CVE-2017-6196 artifex vulnerability CVSS: 6.8 24 Feb 2017, 04:59 UTC

Multiple use-after-free vulnerabilities in the gx_image_enum_begin function in base/gxipixel.c in Ghostscript before ecceafe3abba2714ef9b432035fe0739d9b1a283 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PostScript document.

CVE-2016-8674 artifex vulnerability CVSS: 4.3 15 Feb 2017, 21:59 UTC

The pdf_to_num function in pdf-object.c in MuPDF before 1.10 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted file.

CVE-2017-5896 artifex vulnerability CVSS: 4.3 15 Feb 2017, 19:59 UTC

Heap-based buffer overflow in the fz_subsample_pixmap function in fitz/pixmap.c in MuPDF 1.10a allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted image.

CVE-2017-5991 artifex vulnerability CVSS: 5.0 15 Feb 2017, 06:59 UTC

An issue was discovered in Artifex MuPDF before 1912de5f08e90af1d9d0a9791f58ba3afdb9d465. The pdf_run_xobject function in pdf-op-run.c encounters a NULL pointer dereference during a Fitz fz_paint_pixmap_with_mask painting operation. Versions 1.11 and later are unaffected.

CVE-2016-9108 artifex vulnerability CVSS: 5.0 03 Feb 2017, 15:59 UTC

Integer overflow in the js_regcomp function in regexp.c in Artifex Software, Inc. MuJS before commit b6de34ac6d8bb7dd5461c57940acfbd3ee7fd93e allows attackers to cause a denial of service (application crash) via a crafted regular expression.

CVE-2017-5628 artifex vulnerability CVSS: 6.8 30 Jan 2017, 04:59 UTC

An issue was discovered in Artifex Software, Inc. MuJS before 8f62ea10a0af68e56d5c00720523ebcba13c2e6a. The MakeDay function in jsdate.c does not validate the month, leading to an integer overflow when parsing a specially crafted JS file.

CVE-2017-5627 artifex vulnerability CVSS: 6.8 30 Jan 2017, 04:59 UTC

An issue was discovered in Artifex Software, Inc. MuJS before 4006739a28367c708dea19aeb19b8a1a9326ce08. The jsR_setproperty function in jsrun.c lacks a check for a negative array length. This leads to an integer overflow in the js_pushstring function in jsrun.c when parsing a specially crafted JS file.

CVE-2016-9109 artifex vulnerability CVSS: 5.0 18 Jan 2017, 17:59 UTC

Artifex Software MuJS allows attackers to cause a denial of service (crash) via vectors related to incomplete escape sequences. NOTE: this vulnerability exists due to an incomplete fix for CVE-2016-7563.

CVE-2016-7564 artifex vulnerability CVSS: 5.0 18 Jan 2017, 17:59 UTC

Heap-based buffer overflow in the Fp_toString function in jsfunction.c in Artifex Software MuJS allows attackers to cause a denial of service (crash) via crafted input.

CVE-2016-7563 artifex vulnerability CVSS: 5.0 18 Jan 2017, 17:59 UTC

The chartorune function in Artifex Software MuJS allows attackers to cause a denial of service (out-of-bounds read) via a * (asterisk) at the end of the input.

CVE-2016-10141 artifex vulnerability CVSS: 7.5 13 Jan 2017, 09:59 UTC

An integer overflow vulnerability was observed in the regemit function in regexp.c in Artifex Software, Inc. MuJS before fa3d30fd18c348bb4b1f3858fb860f4fcd4b2045. The attack requires a regular expression with nested repetition. A successful exploitation of this issue can lead to code execution or a denial of service (buffer overflow) condition.

CVE-2016-9294 artifex vulnerability CVSS: 5.0 12 Nov 2016, 00:59 UTC

Artifex Software, Inc. MuJS before 5008105780c0b0182ea6eda83ad5598f225be3ee allows context-dependent attackers to conduct "denial of service (application crash)" attacks by using the "malformed labeled break/continue in JavaScript" approach, related to a "NULL pointer dereference" issue affecting the jscompile.c component.

CVE-2016-9136 artifex vulnerability CVSS: 5.0 03 Nov 2016, 10:59 UTC

Artifex Software, Inc. MuJS before a0ceaf5050faf419401fe1b83acfa950ec8a8a89 allows context-dependent attackers to obtain sensitive information by using the "crafted JavaScript" approach, related to a "Buffer Over-read" issue.

CVE-2016-7506 artifex vulnerability CVSS: 5.0 29 Oct 2016, 01:59 UTC

An out-of-bounds read vulnerability was observed in Sp_replace_regexp function of Artifex Software, Inc. MuJS before 5000749f5afe3b956fc916e407309de840997f4a. A successful exploitation of this issue can lead to code execution or denial of service condition.

CVE-2016-7505 artifex vulnerability CVSS: 7.5 29 Oct 2016, 01:59 UTC

A buffer overflow vulnerability was observed in divby function of Artifex Software, Inc. MuJS before 8c805b4eb19cf2af689c860b77e6111d2ee439d5. A successful exploitation of this issue can lead to code execution or denial of service condition.

CVE-2016-7504 artifex vulnerability CVSS: 7.5 29 Oct 2016, 01:59 UTC

A use-after-free vulnerability was observed in Rp_toString function of Artifex Software, Inc. MuJS before 5c337af4b3df80cf967e4f9f6a21522de84b392a. A successful exploitation of this issue can lead to code execution or denial of service condition.

CVE-2016-9017 artifex vulnerability CVSS: 5.0 28 Oct 2016, 15:59 UTC

Artifex Software, Inc. MuJS before a5c747f1d40e8d6659a37a8d25f13fb5acf8e767 allows context-dependent attackers to obtain sensitive information by using the "opname in crafted JavaScript file" approach, related to an "Out-of-Bounds read" issue affecting the jsC_dumpfunction function in the jsdump.c component.

CVE-2016-6525 artifex vulnerability CVSS: 7.5 22 Sep 2016, 15:59 UTC

Heap-based buffer overflow in the pdf_load_mesh_params function in pdf/pdf-shade.c in MuPDF allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a large decode array.

CVE-2016-6265 artifex vulnerability CVSS: 4.3 22 Sep 2016, 15:59 UTC

Use-after-free vulnerability in the pdf_load_xref function in pdf/pdf-xref.c in MuPDF allows remote attackers to cause a denial of service (crash) via a crafted PDF file.

CVE-2015-3228 artifex vulnerability CVSS: 6.8 11 Aug 2015, 14:59 UTC

Integer overflow in the gs_heap_alloc_bytes function in base/gsmalloc.c in Ghostscript 9.15 and earlier allows remote attackers to cause a denial of service (crash) via a crafted Postscript (ps) file, as demonstrated by using the ps2pdf command, which triggers an out-of-bounds read or write.

CVE-2014-2013 artifex vulnerability CVSS: 7.5 03 Mar 2014, 16:55 UTC

Stack-based buffer overflow in the xps_parse_color function in xps/xps-common.c in MuPDF 1.3 and earlier allows remote attackers to execute arbitrary code via a large number of entries in the ContextColor value of the Fill attribute in a Path element.

CVE-2013-6629 artifex vulnerability CVSS: 5.0 19 Nov 2013, 04:50 UTC

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

CVE-2012-4875 artifex vulnerability CVSS: 9.3 06 Sep 2012, 21:55 UTC

Heap-based buffer overflow in gdevwpr2.c in Ghostscript 9.04, when processing the OutputFile device parameter, allows user-assisted remote attackers to execute arbitrary code via a long file name in a PostScript document. NOTE: as of 20120314, the developer was not able to reproduce the issue and disputed it

CVE-2011-0341 artifex vulnerability CVSS: 9.3 13 May 2011, 17:05 UTC

Stack-based buffer overflow in the pdfmoz_onmouse function in apps/mozilla/moz_main.c in the MuPDF plug-in 2008.09.02 for Firefox allows remote attackers to execute arbitrary code via a crafted web site.

CVE-2010-4054 artifex vulnerability CVSS: 4.3 23 Oct 2010, 20:39 UTC

The gs_type2_interpret function in Ghostscript allows remote attackers to cause a denial of service (incorrect pointer dereference and application crash) via crafted font data in a compressed data stream, aka bug 691043.

CVE-2009-3743 artifex vulnerability CVSS: 9.3 26 Aug 2010, 21:00 UTC

Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer overflow.

CVE-2010-2055 artifex vulnerability CVSS: 7.2 22 Jul 2010, 05:43 UTC

Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program, as demonstrated using gs_init.ps, a different vulnerability than CVE-2010-4820.

CVE-2009-4897 artifex vulnerability CVSS: 9.3 22 Jul 2010, 05:40 UTC

Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document containing a long name.

CVE-2010-1628 artifex vulnerability CVSS: 9.3 19 May 2010, 22:30 UTC

Ghostscript 8.64, 8.70, and possibly other versions allows context-dependent attackers to execute arbitrary code via a PostScript file containing unlimited recursive procedure invocations, which trigger memory corruption in the stack of the interpreter.

CVE-2010-1869 artifex vulnerability CVSS: 9.3 12 May 2010, 11:46 UTC

Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a crafted PostScript file.