Show filters
230 Total Results
Displaying 31-40 of 230
Sort by:
Attacker Value
Unknown
CVE-2023-38559
Disclosure Date: August 01, 2023 (last updated April 25, 2024)
A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.
0
Attacker Value
Unknown
CVE-2021-33796
Disclosure Date: July 07, 2023 (last updated October 08, 2023)
In MuJS before version 1.1.2, a use-after-free flaw in the regexp source property access may cause denial of service.
0
Attacker Value
Unknown
CVE-2023-36664
Disclosure Date: June 25, 2023 (last updated October 08, 2023)
Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
0
Attacker Value
Unknown
CVE-2021-33797
Disclosure Date: April 17, 2023 (last updated October 08, 2023)
Buffer-overflow in jsdtoa.c in Artifex MuJS in versions 1.0.1 to 1.1.1. An integer overflow happens when js_strtod() reads in floating point exponent, which leads to a buffer overflow in the pointer *d.
0
Attacker Value
Unknown
CVE-2022-44789
Disclosure Date: November 23, 2022 (last updated October 08, 2023)
A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file.
0
Attacker Value
Unknown
CVE-2021-4216
Disclosure Date: August 26, 2022 (last updated October 08, 2023)
A Floating point exception (division-by-zero) flaw was found in Mupdf for zero width pages in muraster.c. It is fixed in Mupdf-1.20.0-rc1 upstream.
0
Attacker Value
Unknown
CVE-2020-27792
Disclosure Date: August 19, 2022 (last updated April 24, 2024)
A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF file, triggering the heap buffer overflow that could lead to memory corruption or a denial of service.
0
Attacker Value
Unknown
CVE-2022-2085
Disclosure Date: June 16, 2022 (last updated November 29, 2024)
A NULL pointer dereference vulnerability was found in Ghostscript, which occurs when it tries to render a large number of bits in memory. When allocating a buffer device, it relies on an init_device_procs defined for the device that uses it as a prototype that depends upon the number of bits per pixel. For bpp > 64, mem_x_device is used and does not have an init_device_procs defined. This flaw allows an attacker to parse a large number of bits (more than 64 bits per pixel), which triggers a NULL pointer dereference flaw, causing an application to crash.
0
Attacker Value
Unknown
CVE-2022-30975
Disclosure Date: May 18, 2022 (last updated October 07, 2023)
In Artifex MuJS through 1.2.0, jsP_dumpsyntax in jsdump.c has a NULL pointer dereference, as demonstrated by mujs-pp.
0
Attacker Value
Unknown
CVE-2022-30974
Disclosure Date: May 18, 2022 (last updated October 07, 2023)
compile in regexp.c in Artifex MuJS through 1.2.0 results in stack consumption because of unlimited recursion, a different issue than CVE-2019-11413.
0