Show filters
203 Total Results
Displaying 11-20 of 203
Sort by:
Attacker Value
Unknown

CVE-2024-46953

Disclosure Date: November 10, 2024 (last updated November 14, 2024)
An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.
Attacker Value
Unknown

CVE-2024-46952

Disclosure Date: November 10, 2024 (last updated November 14, 2024)
An issue was discovered in pdf/pdf_xref.c in Artifex Ghostscript before 10.04.0. There is a buffer overflow during handling of a PDF XRef stream (related to W array values).
Attacker Value
Unknown

CVE-2024-46951

Disclosure Date: November 10, 2024 (last updated November 14, 2024)
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.
Attacker Value
Unknown

CVE-2024-43409

Disclosure Date: August 20, 2024 (last updated August 27, 2024)
Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information. This security vulnerability is present in Ghost v4.46.0-v5.89.4. v5.89.5 contains a fix for this issue.
Attacker Value
Unknown

CVE-2024-6420

Disclosure Date: July 23, 2024 (last updated July 23, 2024)
The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.
0
Attacker Value
Unknown

CVE-2024-29509

Disclosure Date: July 03, 2024 (last updated August 03, 2024)
Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle.
Attacker Value
Unknown

CVE-2024-29508

Disclosure Date: July 03, 2024 (last updated August 03, 2024)
Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.
Attacker Value
Unknown

CVE-2024-29506

Disclosure Date: July 03, 2024 (last updated August 03, 2024)
Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name.
Attacker Value
Unknown

CVE-2023-34001

Disclosure Date: June 04, 2024 (last updated June 04, 2024)
Improper Restriction of Excessive Authentication Attempts vulnerability in WPPlugins – WordPress Security Plugins Hide My WP Ghost allows Functionality Bypass.This issue affects Hide My WP Ghost: from n/a through 5.0.25.
0
Attacker Value
Unknown

CVE-2024-34559

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Insertion of Sensitive Information into Log File vulnerability in Ghost Foundation Ghost.This issue affects Ghost: from n/a through 1.4.0.
0