Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown

CVE-2018-18284

Disclosure Date: October 19, 2018 (last updated November 08, 2023)
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator.
0
Attacker Value
Unknown

CVE-2018-16513

Disclosure Date: September 05, 2018 (last updated November 08, 2023)
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the setcolor function to crash the interpreter or possibly have unspecified other impact.
0
Attacker Value
Unknown

CVE-2018-16509

Disclosure Date: September 05, 2018 (last updated November 08, 2023)
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction.
0
Attacker Value
Unknown

CVE-2018-16510

Disclosure Date: September 05, 2018 (last updated November 08, 2023)
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect exec stack handling in the "CS" and "SC" PDF primitives could be used by remote attackers able to supply crafted PDFs to crash the interpreter or possibly have unspecified other impact.
0
Attacker Value
Unknown

CVE-2018-15911

Disclosure Date: August 28, 2018 (last updated November 08, 2023)
In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode operator to crash the interpreter or potentially execute code.
0
Attacker Value
Unknown

CVE-2018-15909

Disclosure Date: August 27, 2018 (last updated November 08, 2023)
In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScript files to crash the interpreter or potentially execute code.
0
Attacker Value
Unknown

CVE-2018-15910

Disclosure Date: August 27, 2018 (last updated November 08, 2023)
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the LockDistillerParams parameter to crash the interpreter or execute code.
0
Attacker Value
Unknown

CVE-2016-9601

Disclosure Date: April 24, 2018 (last updated November 08, 2023)
ghostscript before version 9.21 is vulnerable to a heap based buffer overflow that was found in the ghostscript jbig2_decode_gray_scale_image function which is used to decode halftone segments in a JBIG2 image. A document (PostScript or PDF) with an embedded, specially crafted, jbig2 image could trigger a segmentation fault in ghostscript.
0
Attacker Value
Unknown

CVE-2013-6629

Disclosure Date: November 19, 2013 (last updated October 05, 2023)
The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.
0
Attacker Value
Unknown

CVE-2012-4875

Disclosure Date: September 06, 2012 (last updated November 08, 2023)
Heap-based buffer overflow in gdevwpr2.c in Ghostscript 9.04, when processing the OutputFile device parameter, allows user-assisted remote attackers to execute arbitrary code via a long file name in a PostScript document. NOTE: as of 20120314, the developer was not able to reproduce the issue and disputed it
0