← Back

Ghostscript

ghostscript

Vendor: Artifex • 129 CVEs

CVEs (129)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Artifex
Fedoraproject
2Fedora
Ghostscript
Jun 17, 2026
Jun 16, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A NULL pointer dereference vulnerability was found in Ghostscript, which occurs when it tries to render a large number of bits in memory. When allocating a buffer device, it relies on an init_device_procs defined for the...Show more
A NULL pointer dereference vulnerability was found in Ghostscript, which occurs when it tries to render a large number of bits in memory. When allocating a buffer device, it relies on an init_device_procs defined for the device that uses it as a prototype that depends upon the number of bits per pixel. For bpp > 64, mem_x_device is used and does not have an init_device_procs defined. This flaw allows an attacker to parse a large number of bits (more than 64 bits per pixel), which triggers a NULL pointer dereference flaw, causing an application to crash.Show less
2Artifex
Debian
2Debian Linux
Ghostscript
Jun 17, 2026
Apr 25, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
2Artifex
Fedoraproject
2Fedora
Ghostscript
Jun 17, 2026
Feb 16, 2022
N/A· v4
9.9 CRITICAL· v3
9.3 HIGH· v2
A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary...Show more
A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript interpreter. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.Show less
2Artifex
Debian
2Debian Linux
Ghostscript
Jun 17, 2026
Jan 1, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).
2Artifex
Debian
2Debian Linux
Ghostscript
Jun 17, 2026
Jan 1, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp).
2Artifex
Redhat
2Enterprise Linux
Ghostscript
Jun 17, 2026
Sep 3, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25. A local attacker could supply a specially crafted PDF file to cause a denial of service.
3Artifex
CanonicalDebian
3Debian Linux
GhostscriptUbuntu Linux
Jun 17, 2026
Aug 13, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A buffer overflow vulnerability in GetNumSameData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript from v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fi...Show more
A buffer overflow vulnerability in GetNumSameData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript from v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.Show less
3Artifex
CanonicalDebian
3Debian Linux
GhostscriptUbuntu Linux
Jun 17, 2026
Aug 13, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A division by zero vulnerability in dot24_print_page() in devices/gdevdm24.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
3Artifex
CanonicalDebian
3Debian Linux
GhostscriptUbuntu Linux
Jun 17, 2026
Aug 13, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A buffer overflow vulnerability in lxm5700m_print_page() in devices/gdevlxm.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted eps file. This is fixed in v9.51.
3Artifex
CanonicalDebian
3Debian Linux
GhostscriptUbuntu Linux
Jun 17, 2026
Aug 13, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A buffer overflow vulnerability in p_print_image() in devices/gdevcdj.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
3Artifex
CanonicalDebian
3Debian Linux
GhostscriptUbuntu Linux
Jun 17, 2026
Aug 13, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A null pointer dereference vulnerability in devices/vector/gdevtxtw.c and psi/zbfont.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fi...Show more
A null pointer dereference vulnerability in devices/vector/gdevtxtw.c and psi/zbfont.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fixed in v9.51.Show less
3Artifex
CanonicalDebian
3Debian Linux
GhostscriptUbuntu Linux
Jun 17, 2026
Aug 13, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A null pointer dereference vulnerability in devices/gdevtsep.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fixed in v9.51.
3Artifex
CanonicalDebian
3Debian Linux
GhostscriptUbuntu Linux
Jun 17, 2026
Aug 13, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A buffer overflow vulnerability in pcx_write_rle() in contrib/japanese/gdev10v.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
3Artifex
CanonicalDebian
3Debian Linux
GhostscriptUbuntu Linux
Jun 17, 2026
Aug 13, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A buffer overflow vulnerability in image_render_color_thresh() in base/gxicolor.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to escalate privileges via a crafted eps file. This is fixed in v9...Show more
A buffer overflow vulnerability in image_render_color_thresh() in base/gxicolor.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to escalate privileges via a crafted eps file. This is fixed in v9.51.Show less
3Artifex
CanonicalDebian
3Debian Linux
GhostscriptUbuntu Linux
Jun 17, 2026
Aug 13, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A use-after-free vulnerability in xps_finish_image_path() in devices/vector/gdevxps.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51.
3Artifex
CanonicalDebian
3Debian Linux
GhostscriptUbuntu Linux
Jun 17, 2026
Aug 13, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51.
3Artifex
CanonicalDebian
3Debian Linux
GhostscriptUbuntu Linux
Jun 17, 2026
Aug 13, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A buffer overflow vulnerability in okiibm_print_page1() in devices/gdevokii.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
3Artifex
CanonicalDebian
3Debian Linux
GhostscriptUbuntu Linux
Jun 17, 2026
Aug 13, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A buffer overflow vulnerability in tiff12_print_page() in devices/gdevtfnx.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
3Artifex
CanonicalDebian
3Debian Linux
GhostscriptUbuntu Linux
Jun 17, 2026
Aug 13, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A Division by Zero vulnerability in bj10v_print_page() in contrib/japanese/gdev10v.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9...Show more
A Division by Zero vulnerability in bj10v_print_page() in contrib/japanese/gdev10v.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.Show less
3Artifex
CanonicalDebian
3Debian Linux
GhostscriptUbuntu Linux
Jun 17, 2026
Aug 13, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A buffer overflow vulnerability in mj_color_correct() in contrib/japanese/gdevmjc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9....Show more
A buffer overflow vulnerability in mj_color_correct() in contrib/japanese/gdevmjc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.Show less