CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Artifex Debian2Afpl Ghostscript Debian LinuxMay 13, 2026 Mar 7, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER" argument, which allows remote attackers to read data via a crafted postscript file. |
Multiple use-after-free vulnerabilities in the gx_image_enum_begin function in base/gxipixel.c in Ghostscript before ecceafe3abba2714ef9b432035fe0739d9b1a283 allow remote attackers to cause a denial of service (applicati...Show more |
Integer overflow in the gs_heap_alloc_bytes function in base/gsmalloc.c in Ghostscript 9.15 and earlier allows remote attackers to cause a denial of service (crash) via a crafted Postscript (ps) file, as demonstrated by...Show more |
1Artifex 3Afpl Ghostscript Ghostscript FontsGpl GhostscriptApr 29, 2026 Oct 23, 2010 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The gs_type2_interpret function in Ghostscript allows remote attackers to cause a denial of service (incorrect pointer dereference and application crash) via crafted font data in a compressed data stream, aka bug 691043. |
1Artifex 3Afpl Ghostscript Ghostscript FontsGpl GhostscriptApr 29, 2026 Aug 26, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a ma...Show more |
1Artifex 3Afpl Ghostscript Ghostscript FontsGpl GhostscriptApr 29, 2026 Jul 22, 2010 N/A· v4 N/A· v3 7.2 HIGH· v2 Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -...Show more |
1Artifex 3Afpl Ghostscript Ghostscript FontsGpl GhostscriptApr 29, 2026 Jul 22, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document containing a long name. |