← Back

Ghostscript

ghostscript

Vendor: Artifex • 129 CVEs

CVEs (129)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Artifex
1Ghostscript
Jun 17, 2026
Jul 3, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be...Show more
An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a transformation of ../../foo to ./../../foo and this will grant access if ./ is permitted.Show less
1Artifex
1Ghostscript
Jun 17, 2026
Jul 3, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on u...Show more
An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of %pipe% can be bypassed via the aa/../%pipe%command# output filename.Show less
1Artifex
1Ghostscript
Jun 17, 2026
Jul 3, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, expl...Show more
Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.Show less
1Artifex
1Ghostscript
Jun 17, 2026
Jul 3, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.
1Artifex
1Ghostscript
Jun 17, 2026
Jul 3, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.
1Artifex
1Ghostscript
Jun 17, 2026
Jul 3, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle.
1Artifex
1Ghostscript
Jun 17, 2026
Jul 3, 2024
N/A· v4
3.3 LOW· v3
N/A· v2
Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.
1Artifex
1Ghostscript
Jun 17, 2026
Jul 3, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name.
1Artifex
1Ghostscript
Jun 17, 2026
Apr 28, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue was discovered in Artifex Ghostscript before 10.03.1. psi/zmisc1.c, when SAFER mode is used, allows eexec seeds other than the Type 1 standard.
1Artifex
1Ghostscript
Jun 17, 2026
Feb 4, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e...Show more
Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).Show less
1Artifex
1Ghostscript
Jun 17, 2026
Dec 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10.02.0 allows remote attackers to crash the application via a dangling pointer.
2Artifex
Fedoraproject
2Fedora
Ghostscript
Jun 17, 2026
Sep 18, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER h...Show more
In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated. NOTE: it is a documented risk that the IJS server can be specified on a gs command line (the IJS device inherently must execute a command to start the IJS server).Show less
2Artifex
Redhat
9Codeready Linux Builder
Codeready Linux Builder For Arm64Codeready Linux Builder For Ibm Z Systems+6 more
Jun 17, 2026
Aug 23, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat E...Show more
A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat Enterprise Linux 8.Show less
1Artifex
1Ghostscript
Jun 17, 2026
Aug 22, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Buffer Overflow vulnerability in clj_media_size function in devices/gdevclj.c in Artifex Ghostscript 9.50 allows remote attackers to cause a denial of service or other unspecified impact(s) via opening of crafted PDF doc...Show more
Buffer Overflow vulnerability in clj_media_size function in devices/gdevclj.c in Artifex Ghostscript 9.50 allows remote attackers to cause a denial of service or other unspecified impact(s) via opening of crafted PDF document.Show less
1Artifex
1Ghostscript
Jun 17, 2026
Aug 22, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A divide by zero issue discovered in eps_print_page in gdevepsn.c in Artifex Software GhostScript 9.50 allows remote attackers to cause a denial of service via opening of crafted PDF file.
1Artifex
1Ghostscript
Jun 17, 2026
Aug 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local attacker to cause a denial of service via transforming a crafted PCL file to PDF format.
4Artifex
DebianFedoraproject+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Jun 23, 2026
Aug 1, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with...Show more
A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.Show less
3Artifex
DebianFedoraproject
3Debian Linux
FedoraGhostscript
Jun 17, 2026
Jun 25, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
2Artifex
Debian
2Debian Linux
Ghostscript
Jun 17, 2026
Mar 31, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDe...Show more
In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.Show less
2Artifex
Debian
2Debian Linux
Ghostscript
Jun 17, 2026
Aug 19, 2022
N/A· v4
7.1 HIGH· v3
N/A· v2
A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the hea...Show more
A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.Show less