Show filters
230 Total Results
Displaying 101-110 of 230
Sort by:
Attacker Value
Unknown
CVE-2019-6131
Disclosure Date: January 11, 2019 (last updated November 08, 2023)
svg-run.c in Artifex MuPDF 1.14.0 has infinite recursion with stack consumption in svg_run_use_symbol, svg_run_element, and svg_run_use, as demonstrated by mutool.
0
Attacker Value
Unknown
CVE-2019-6130
Disclosure Date: January 11, 2019 (last updated November 08, 2023)
Artifex MuPDF 1.14.0 has a SEGV in the function fz_load_page of the fitz/document.c file, as demonstrated by mutool. This is related to page-number mishandling in cbz/mucbz.c, cbz/muimg.c, and svg/svg-doc.c.
0
Attacker Value
Unknown
CVE-2018-19478
Disclosure Date: January 02, 2019 (last updated November 08, 2023)
In Artifex Ghostscript before 9.26, a carefully crafted PDF file can trigger an extremely long running computation when parsing the file.
0
Attacker Value
Unknown
CVE-2018-19134
Disclosure Date: December 20, 2018 (last updated November 08, 2023)
In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscript process. This is a type confusion issue because of failure to check whether the Implementation of a pattern dictionary was a structure type.
0
Attacker Value
Unknown
CVE-2018-19881
Disclosure Date: December 06, 2018 (last updated November 08, 2023)
In Artifex MuPDF 1.14.0, svg/svg-run.c allows remote attackers to cause a denial of service (recursive calls followed by a fitz/xml.c fz_xml_att crash from excessive stack consumption) via a crafted svg file, as demonstrated by mupdf-gl.
0
Attacker Value
Unknown
CVE-2018-19882
Disclosure Date: December 06, 2018 (last updated November 08, 2023)
In Artifex MuPDF 1.14.0, the svg_run_image function in svg/svg-run.c allows remote attackers to cause a denial of service (href_att NULL pointer dereference and application crash) via a crafted svg file, as demonstrated by mupdf-gl.
0
Attacker Value
Unknown
CVE-2018-16863
Disclosure Date: December 03, 2018 (last updated November 27, 2024)
It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSAFER protection to, for example, execute arbitrary shell commands via a specially crafted PostScript document. This only affects ghostscript 9.07 as shipped with Red Hat Enterprise Linux 7.
0
Attacker Value
Unknown
CVE-2018-19777
Disclosure Date: November 30, 2018 (last updated November 08, 2023)
In Artifex MuPDF 1.14.0, there is an infinite loop in the function svg_dev_end_tile in fitz/svg-device.c, as demonstrated by mutool.
0
Attacker Value
Unknown
CVE-2018-19477
Disclosure Date: November 23, 2018 (last updated November 08, 2023)
psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a JBIG2Decode type confusion.
0
Attacker Value
Unknown
CVE-2018-19475
Disclosure Date: November 23, 2018 (last updated November 08, 2023)
psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same.
0