Known Vulnerabilities for Gpl Ghostscript by Artifex

Listed below are 10 of the newest known vulnerabilities associated with "Gpl Ghostscript" by "Artifex".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2018-18284 Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Pol... 8.6 - HIGH 2018-10-19 2023-11-07
CVE-2018-16513 In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the setco... 7.8 - HIGH 2018-09-05 2023-11-07
CVE-2018-16510 An issue was discovered in Artifex Ghostscript before 9.24. Incorrect exec stack handling in the "CS" and "SC" PDF primitives... 7.8 - HIGH 2018-09-05 2023-11-07
CVE-2018-16509 An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of ... 7.8 - HIGH 2018-09-05 2023-11-07
CVE-2018-15911 In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory acc... 7.8 - HIGH 2018-08-28 2023-11-07
CVE-2018-15910 In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the LockD... 7.8 - HIGH 2018-08-27 2023-11-07
CVE-2018-15909 In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to... 7.8 - HIGH 2018-08-27 2023-11-07
CVE-2016-9601 ghostscript before version 9.21 is vulnerable to a heap based buffer overflow that was found in the ghostscript jbig2_decode_... 5.5 - MEDIUM 2018-04-24 2023-11-07
CVE-2013-6629 The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.... 5 - MEDIUM 2013-11-19 2023-06-21
CVE-2012-4875 ** DISPUTED ** Heap-based buffer overflow in gdevwpr2.c in Ghostscript 9.04, when processing the OutputFile device parameter... 9.3 - HIGH 2012-09-06 2023-11-07

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationArtifexGpl Ghostscript9.26AllAllAll
ApplicationArtifexGpl Ghostscript9.21AllAllAll
ApplicationArtifexGpl Ghostscript9.2AllAllAll
ApplicationArtifexGpl Ghostscript9.19AllAllAll
ApplicationArtifexGpl Ghostscript9.18AllAllAll
ApplicationArtifexGpl Ghostscript9.16AllAllAll
ApplicationArtifexGpl Ghostscript9.15AllAllAll
ApplicationArtifexGpl Ghostscript9.14AllAllAll
ApplicationArtifexGpl Ghostscript9.1AllAllAll
ApplicationArtifexGpl Ghostscript9.09AllAllAll
ApplicationArtifexGpl Ghostscript9.07AllAllAll
ApplicationArtifexGpl Ghostscript9.06AllAllAll
ApplicationArtifexGpl Ghostscript9.05AllAllAll
ApplicationArtifexGpl Ghostscript9.04AllAllAll
ApplicationArtifexGpl Ghostscript9.02AllAllAll
ApplicationArtifexGpl Ghostscript9.01AllAllAll
ApplicationArtifexGpl Ghostscript9.00AllAllAll
ApplicationArtifexGpl Ghostscript9AllAllAll
ApplicationArtifexGpl Ghostscript8.71AllAllAll
ApplicationArtifexGpl Ghostscript8.70AllAllAll
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report