Show filters
230 Total Results
Displaying 41-50 of 230
Sort by:
Attacker Value
Unknown

CVE-2019-25059

Disclosure Date: April 25, 2022 (last updated October 07, 2023)
Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
Attacker Value
Unknown

CVE-2022-1350

Disclosure Date: April 14, 2022 (last updated October 07, 2023)
A vulnerability classified as problematic was found in GhostPCL 9.55.0. This vulnerability affects the function chunk_free_object of the file gsmchunk.c. The manipulation with a malicious file leads to a memory corruption. The attack can be initiated remotely but requires user interaction. The exploit has been disclosed to the public as a POC and may be used. It is recommended to apply the patches to fix this issue.
Attacker Value
Unknown

CVE-2021-3781

Disclosure Date: February 16, 2022 (last updated November 29, 2024)
A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript interpreter. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Attacker Value
Unknown

CVE-2021-45005

Disclosure Date: February 14, 2022 (last updated October 07, 2023)
Artifex MuJS v1.1.3 was discovered to contain a heap buffer overflow which is caused by conflicting JumpList of nested try/finally statements.
Attacker Value
Unknown

CVE-2021-45949

Disclosure Date: January 01, 2022 (last updated October 07, 2023)
Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).
Attacker Value
Unknown

CVE-2021-45944

Disclosure Date: January 01, 2022 (last updated October 07, 2023)
Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp).
Attacker Value
Unknown

CVE-2021-37220

Disclosure Date: July 21, 2021 (last updated November 08, 2023)
MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.
Attacker Value
Unknown

CVE-2020-19609

Disclosure Date: July 21, 2021 (last updated November 08, 2023)
Artifex MuPDF before 1.18.0 has a heap based buffer over-write in tiff_expand_colormap() function when parsing TIFF files allowing attackers to cause a denial of service.
Attacker Value
Unknown

CVE-2020-22885

Disclosure Date: July 13, 2021 (last updated November 28, 2024)
Buffer overflow vulnerability in mujs before 1.0.8 due to recursion in the GC scanning phase, allows remote attackers to cause a denial of service.
Attacker Value
Unknown

CVE-2020-22886

Disclosure Date: July 13, 2021 (last updated November 28, 2024)
Buffer overflow vulnerability in function jsG_markobject in jsgc.c in mujs before 1.0.8, allows remote attackers to cause a denial of service.