Show filters
230 Total Results
Displaying 91-100 of 230
Sort by:
Attacker Value
Unknown

CVE-2019-7321

Disclosure Date: June 13, 2019 (last updated July 18, 2024)
Usage of an uninitialized variable in the function fz_load_jpeg in Artifex MuPDF 1.14 can result in a heap overflow vulnerability that allows an attacker to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2019-12798

Disclosure Date: June 13, 2019 (last updated November 08, 2023)
An issue was discovered in Artifex MuJS 1.0.5. regcompx in regexp.c does not restrict regular expression program size, leading to an overflow of the parsed syntax list size.
0
Attacker Value
Unknown

CVE-2017-15652

Disclosure Date: May 23, 2019 (last updated November 08, 2023)
Artifex Ghostscript 9.22 is affected by: Obtain Information. The impact is: obtain sensitive information. The component is: affected source code file, affected function, affected executable, affected libga (imagemagick used that). The attack vector is: Someone must open a postscript file though ghostscript. Because of imagemagick also use libga, so it was affected as well.
0
Attacker Value
Unknown

CVE-2019-3839

Disclosure Date: May 16, 2019 (last updated November 08, 2023)
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.
Attacker Value
Unknown

CVE-2019-11413

Disclosure Date: April 22, 2019 (last updated November 08, 2023)
An issue was discovered in Artifex MuJS 1.0.5. It has unlimited recursion because the match function in regexp.c lacks a depth check.
0
Attacker Value
Unknown

CVE-2019-11411

Disclosure Date: April 22, 2019 (last updated November 08, 2023)
An issue was discovered in Artifex MuJS 1.0.5. The Number#toFixed() and numtostr implementations in jsnumber.c have a stack-based buffer overflow.
0
Attacker Value
Unknown

CVE-2019-11412

Disclosure Date: April 22, 2019 (last updated November 08, 2023)
An issue was discovered in Artifex MuJS 1.0.5. jscompile.c can cause a denial of service (invalid stack-frame jump) because it lacks an ENDTRY opcode call.
Attacker Value
Unknown

CVE-2019-3838

Disclosure Date: March 25, 2019 (last updated November 08, 2023)
It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.
Attacker Value
Unknown

CVE-2019-3835

Disclosure Date: March 25, 2019 (last updated November 08, 2023)
It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.
Attacker Value
Unknown

CVE-2019-6116

Disclosure Date: March 21, 2019 (last updated November 08, 2023)
In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.