Artifex
Artifex Ghostscript: vulnerabilidades y CVE
Artifex Ghostscript tiene 130 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 12 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE130
Últimos 12 meses1
Críticas12
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2017-8291 | Alta (7.8) | 97% | ⚠ Explotación activa | 27 abr 2017 | Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-103226 | Baja (2.1) | 0.44% | — | 30 sept 2026 | A vulnerability was identified in Artifex Ghostscript up to 10.09.0. Affected is the function type1_callsubr of the file devices/vector/gdevpsfx.c of the component Pdfwrite. The manipulation leads to stack-based buffer… |
| CVE-2025-59800 | Media (5.5) | 0.18% | — | 22 sept 2025 | In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8. |
| CVE-2025-59799 | Media (5.5) | 0.20% | — | 22 sept 2025 | Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdfmark_coerce_dest in devices/vector/gdevpdfm.c via a large size value. |
| CVE-2025-59798 | Media (5.5) | 0.20% | — | 22 sept 2025 | Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c. |
| CVE-2025-48708 | Baja (3.3) | 0.32% | — | 23 may 2025 | gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext. |
| CVE-2025-46646 | Media (4.5) | 0.18% | — | 26 abr 2025 | In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954. |
| CVE-2025-27837 | Crítica (9.8) | 0.60% | — | 25 mar 2025 | An issue was discovered in Artifex Ghostscript before 10.05.0. Access to arbitrary files can occur through a truncated path with invalid UTF-8 characters, for base/gp_mswin.c and base/winrtsup.cpp. |
| CVE-2025-27836 | Crítica (9.8) | 0.59% | — | 25 mar 2025 | An issue was discovered in Artifex Ghostscript before 10.05.0. The BJ10V device has a Print buffer overflow in contrib/japanese/gdev10v.c. |
| CVE-2025-27835 | Alta (7.8) | 0.29% | — | 25 mar 2025 | An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs when converting glyphs to Unicode in psi/zbfont.c. |
| CVE-2025-27834 | Alta (7.8) | 0.26% | — | 25 mar 2025 | An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs via an oversized Type 4 function in a PDF document to pdf/pdf_func.c. |
| CVE-2025-27833 | Alta (7.8) | 0.22% | — | 25 mar 2025 | An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs for a long TTF font name to pdf/pdf_fmap.c. |
| CVE-2025-27832 | Crítica (9.8) | 0.82% | — | 25 mar 2025 | An issue was discovered in Artifex Ghostscript before 10.05.0. The NPDL device has a Compression buffer overflow for contrib/japanese/gdevnpdl.c. |
| CVE-2025-27831 | Crítica (9.8) | 0.59% | — | 25 mar 2025 | An issue was discovered in Artifex Ghostscript before 10.05.0. The DOCXWRITE TXTWRITE device has a text buffer overflow via long characters to devices/vector/doc_common.c. |
| CVE-2025-27830 | Alta (7.8) | 0.30% | — | 25 mar 2025 | An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs during serialization of DollarBlend in a font, for base/write_t1.c and psi/zfapi.c. |
| CVE-2024-46956 | Alta (7.8) | 0.39% | — | 10 nov 2024 | An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution. |
| CVE-2024-46955 | Media (5.5) | 0.29% | — | 10 nov 2024 | An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space. |
| CVE-2024-46954 | Alta (7.8) | 0.55% | — | 10 nov 2024 | An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal. |
| CVE-2024-46953 | Alta (7.8) | 0.39% | — | 10 nov 2024 | An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path… |
| CVE-2024-46952 | Alta (7.8) | 0.32% | — | 10 nov 2024 | An issue was discovered in pdf/pdf_xref.c in Artifex Ghostscript before 10.04.0. There is a buffer overflow during handling of a PDF XRef stream (related to W array values). |
| CVE-2024-46951 | Alta (7.8) | 0.36% | — | 10 nov 2024 | An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution. |
| CVE-2024-33871 | Alta (8.8) | 1.4% | — | 3 jul 2024 | An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the… |
| CVE-2024-33870 | Media (6.3) | 0.52% | — | 3 jul 2024 | An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be… |
| CVE-2024-33869 | Media (5.3) | 0.45% | — | 3 jul 2024 | An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on… |
| CVE-2024-29511 | Alta (7.5) | 1.1% | — | 3 jul 2024 | Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example,… |
| CVE-2024-29510 | Media (6.3) | 28% | — | 3 jul 2024 | Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device. |
| CVE-2024-29507 | Media (5.4) | 0.72% | — | 3 jul 2024 | Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters. |
| CVE-2024-29509 | Alta (8.8) | 1.4% | — | 3 jul 2024 | Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle. |
| CVE-2024-29508 | Baja (3.3) | 0.38% | — | 3 jul 2024 | Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc. |
| CVE-2024-29506 | Alta (8.8) | 0.91% | — | 3 jul 2024 | Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name. |
| CVE-2023-52722 | Media (5.5) | 0.33% | — | 28 abr 2024 | An issue was discovered in Artifex Ghostscript before 10.03.1. psi/zmisc1.c, when SAFER mode is used, allows eexec seeds other than the Type 1 standard. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.