← Back

Artifex

artifex

256 CVEs • 10 products

Products (10)

Click to collapse
Toggle
Ghostscript
ghostscript
Mupdf
mupdf
Mujs
mujs
Jbig2dec
jbig2dec
Gsview
gsview
Ghostpcl
ghostpcl

CVEs (256)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Artifex
CanonicalDebian
3Debian Linux
GhostscriptUbuntu Linux
Nov 21, 2024
Aug 13, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
3Artifex
CanonicalDebian
3Debian Linux
GhostscriptUbuntu Linux
Nov 21, 2024
Aug 13, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A buffer overflow vulnerability in cif_print_page() in devices/gdevcif.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
3Artifex
CanonicalDebian
3Debian Linux
GhostscriptUbuntu Linux
Nov 21, 2024
Aug 13, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A buffer overflow vulnerability in pj_common_print_page() in devices/gdevpjet.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
3Artifex
CanonicalDebian
3Debian Linux
GhostscriptUbuntu Linux
Nov 21, 2024
Aug 13, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A buffer overflow vulnerability in lprn_is_black() in contrib/lips4/gdevlprn.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
3Artifex
CanonicalOpensuse
3Ghostscript
LeapUbuntu Linux
Nov 21, 2024
Jul 28, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in...Show more
A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and could underflow to max uint32_t. This was fixed in commit 5d499272b95a6b890a1397e11d20937de000d31b.Show less
3Artifex
DebianOpensuse
3Debian Linux
Jbig2decLeap
Nov 21, 2024
Apr 27, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow.
2Artifex
Sumatrapdfreader
2Mupdf
Sumatrapdf
Nov 21, 2024
Jan 23, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
SumatraPDF 2.1.1/MuPDF 1.0 allows remote attackers to cause an Integer Overflow in the lex_number() function via a corrupt PDF file.
2Artifex
Fedoraproject
2Fedora
Ghostscript
Nov 21, 2024
Nov 27, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted...Show more
A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.Show less
2Artifex
Redhat
93scale Api Management
Enterprise LinuxEnterprise Linux Desktop+6 more
Nov 21, 2024
Nov 27, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially cra...Show more
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and access files outside of restricted areas.Show less
3Artifex
FedoraprojectOpensuse
3Fedora
GhostscriptLeap
Nov 21, 2024
Nov 15, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker coul...Show more
A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges within the Ghostscript and access files outside of restricted areas or execute commands.Show less
5Artifex
DebianFedoraproject+2 more
12Debian Linux
Enterprise LinuxEnterprise Linux Desktop+9 more
Nov 21, 2024
Sep 6, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted Po...Show more
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.Show less
5Artifex
DebianFedoraproject+2 more
5Debian Linux
FedoraGhostscript+2 more
Nov 21, 2024
Sep 3, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially cra...Show more
A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.Show less
5Artifex
DebianFedoraproject+2 more
5Debian Linux
FedoraGhostscript+2 more
Nov 21, 2024
Sep 3, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafte...Show more
A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.Show less
1Artifex
1Mupdf
Nov 21, 2024
Aug 14, 2019
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
Artifex MuPDF before 1.16.0 has a heap-based buffer over-read in fz_chartorune in fitz/string.c because pdf/pdf-op-filter.c does not check for a missing string.
1Artifex
1Mupdf
Nov 21, 2024
Jul 4, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Artifex MuPDF 1.15.0 has a heap-based buffer overflow in fz_append_display_node located at fitz/list-device.c, allowing remote attackers to execute arbitrary code via a crafted PDF file. This occurs with a large BDC prop...Show more
Artifex MuPDF 1.15.0 has a heap-based buffer overflow in fz_append_display_node located at fitz/list-device.c, allowing remote attackers to execute arbitrary code via a crafted PDF file. This occurs with a large BDC property name that overflows the allocated size of a display list node.Show less
1Artifex
1Mupdf
Nov 21, 2024
Jun 13, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Usage of an uninitialized variable in the function fz_load_jpeg in Artifex MuPDF 1.14 can result in a heap overflow vulnerability that allows an attacker to execute arbitrary code.
1Artifex
1Mujs
Nov 21, 2024
Jun 13, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Artifex MuJS 1.0.5. regcompx in regexp.c does not restrict regular expression program size, leading to an overflow of the parsed syntax list size.
1Artifex
1Ghostscript
Nov 21, 2024
May 23, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Artifex Ghostscript 9.22 is affected by: Obtain Information. The impact is: obtain sensitive information. The component is: affected source code file, affected function, affected executable, affected libga (imagemagick u...Show more
Artifex Ghostscript 9.22 is affected by: Obtain Information. The impact is: obtain sensitive information. The component is: affected source code file, affected function, affected executable, affected libga (imagemagick used that). The attack vector is: Someone must open a postscript file though ghostscript. Because of imagemagick also use libga, so it was affected as well.Show less
6Artifex
CanonicalDebian+3 more
6Debian Linux
Enterprise LinuxFedora+3 more
Nov 21, 2024
May 16, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have acces...Show more
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.Show less
1Artifex
1Mujs
Nov 21, 2024
Apr 22, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Artifex MuJS 1.0.5. It has unlimited recursion because the match function in regexp.c lacks a depth check.