Show filters
148 Total Results
Displaying 141-148 of 148
Sort by:
Attacker Value
Unknown

CVE-2009-0584

Disclosure Date: March 23, 2009 (last updated October 04, 2023)
icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using a device file for processing a crafted image file associated with large integer values for certain sizes, related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
0
Attacker Value
Unknown

CVE-2008-0411

Disclosure Date: February 28, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file containing a long Range array in a .seticcspace operator.
0
Attacker Value
Unknown

CVE-2004-0967

Disclosure Date: February 09, 2005 (last updated February 22, 2025)
The (1) pj-gs.sh, (2) ps2epsi, (3) pv.sh, and (4) sysvlp.sh scripts in the ESP Ghostscript (espgs) package in Trustix Secure Linux 1.5 through 2.1, and other operating systems, allow local users to overwrite files via a symlink attack on temporary files.
0
Attacker Value
Unknown

CVE-2002-0363

Disclosure Date: May 29, 2002 (last updated February 22, 2025)
ghostscript before 6.53 allows attackers to execute arbitrary commands by using .locksafe or .setsafe to reset the current pagedevice.
0
Attacker Value
Unknown

CVE-2001-1353

Disclosure Date: September 18, 2001 (last updated February 22, 2025)
ghostscript before 6.51 allows local users to read and write arbitrary files as the 'lp' user via the file operator, even with -dSAFER enabled.
0
Attacker Value
Unknown

CVE-2000-1163

Disclosure Date: January 09, 2001 (last updated February 22, 2025)
ghostscript before 5.10-16 uses an empty LD_RUN_PATH environmental variable to find libraries in the current directory, which could allow local users to execute commands as other users by placing a Trojan horse library into a directory from which another user executes ghostscript.
0
Attacker Value
Unknown

CVE-2000-1162

Disclosure Date: January 09, 2001 (last updated February 22, 2025)
ghostscript before 5.10-16 allows local users to overwrite files of other users via a symlink attack.
0
Attacker Value
Unknown

CVE-1999-0155

Disclosure Date: August 31, 1995 (last updated February 22, 2025)
The ghostscript command with the -dSAFER option allows remote attackers to execute commands.
0