VendorsArtifexghostscriptany version
Vulnerabilities

Artifex Ghostscript any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

99CVEs
CVE-2020-16293
A null pointer dereference vulnerability in compose_group_nonknockout_nonblend_isolated_allmask_common() in base/gxblend.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
Published 2020-08-13 · Modified
5.5EPSS 0.018
CVE-2018-16539
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect access checking in temp file handling to disclose contents of files on the system otherwise not readable.
Published 2018-09-05 · Modified
5.5EPSS 0.014
CVE-2018-16541
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect free logic in pagedevice replacement to crash the interpreter.
Published 2018-09-05 · Modified
5.5EPSS 0.014
CVE-2021-45949
Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).
Published 2021-12-31 · Modified
5.5EPSS 0.014
CVE-2021-45944
Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp).
Published 2021-12-31 · Modified
5.5EPSS 0.014
CVE-2023-38559
Ghostscript: out-of-bound read in base/gdevdevn.c:1973 in devn_pcx_write_rle could result in dos
Published 2023-08-01 · Modified
5.5EPSS 0.004
CVE-2023-4042
Ghostscript: incomplete fix for cve-2020-16305
Published 2023-08-23 · Modified
5.5EPSS 0.003
CVE-2023-52722
An issue was discovered in Artifex Ghostscript before 10.03.1. psi/zmisc1.c, when SAFER mode is used, allows eexec seeds other than the Type 1 standard.
Published 2024-04-27 · Analyzed
5.5EPSS 0.003
CVE-2023-38560
Ghostscript: integer overflow in pcl/pl/plfont.c:418 in pl_glyph_name
Published 2023-08-01 · Modified
5.5EPSS 0.003
CVE-2024-46955
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space.
Published 2024-11-10 · Modified
5.5EPSS 0.003
CVE-2025-59798
Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c.
Published 2025-09-22 · Modified
5.5EPSS 0.002
CVE-2025-59799
Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdfmark_coerce_dest in devices/vector/gdevpdfm.c via a large size value.
Published 2025-09-22 · Modified
5.5EPSS 0.002
CVE-2025-59800
In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8.
Published 2025-09-22 · Analyzed
5.5EPSS 0.002
CVE-2024-29507
Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.
Published 2024-07-03 · Analyzed
5.4EPSS 0.007
CVE-2018-11645
psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a similar issue to CVE-2016-7977.
Published 2018-06-01 · Modified
5.3EPSS 0.026
CVE-2024-33869
An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of %pipe% can be bypassed via the aa/../%pipe%command# output filename.
Published 2024-07-03 · Analyzed
5.3EPSS 0.005
CVE-2025-46646
In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954.
Published 2025-04-26 · Analyzed
4.5EPSS 0.002
CVE-2025-48708
gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.
Published 2025-05-23 · Analyzed
4.0EPSS 0.003
CVE-2024-29508
Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.
Published 2024-07-03 · Modified
3.3EPSS 0.004
← Prev3 / 3