Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
367 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 1.9% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A buffer overflow vulnerability in okiibm_print_page1() in devices/gdevokii.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 2.0% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A buffer overflow vulnerability in tiff12_print_page() in devices/gdevtfnx.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 1.8% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A Division by Zero vulnerability in bj10v_print_page() in contrib/japanese/gdev10v.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 2.0% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A buffer overflow vulnerability in mj_color_correct() in contrib/japanese/gdevmjc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. | |
| Analizada | Media (5.5) | 2.3% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A buffer overflow vulnerability in FloydSteinbergDitheringC() in contrib/gdevbjca.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 2.1% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A buffer overflow vulnerability in GetNumWrongData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript from v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 1.8% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A null pointer dereference vulnerability in clj_media_size() in devices/gdevclj.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 1.9% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A buffer overflow vulnerability in epsc_print_page() in devices/gdevepsc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 1.8% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A null pointer dereference vulnerability in compose_group_nonknockout_nonblend_isolated_allmask_common() in base/gxblend.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 2.0% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A buffer overflow vulnerability in mj_raster_cmd() in contrib/japanese/gdevmjc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. | |
| Analizada | Media (5.5) | 2.3% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A buffer overflow vulnerability in contrib/gdevdj9.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 2.0% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 2.0% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A buffer overflow vulnerability in cif_print_page() in devices/gdevcif.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 2.0% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A buffer overflow vulnerability in pj_common_print_page() in devices/gdevpjet.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. | |
| Modificada | Media (5.5) | 1.9% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux | 13/8/2020 | 17/6/2026 | A buffer overflow vulnerability in lprn_is_black() in contrib/lips4/gdevlprn.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51. | |
| Modificada | Crítica (9.8) | 5.2% | — | Artifex GhostscriptCanonical Ubuntu LinuxOpensuse Leap | 28/7/2020 | 17/6/2026 | A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and could underflow to max uint32_t. This was fixed in commit… | |
| Modificada | Alta (8.1) | 1.2% | — | Ghost | 20/3/2020 | 17/6/2026 | Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise interact with internal systems. | |
| Modificada | Alta (7.8) | 0.32% | — | Symantec Encryption DesktopSymantec Endpoint EncryptionSymantec Ghost Solution SuiteSymantec IT Management Suite | 8/1/2020 | 17/6/2026 | A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec IT Management Suite 8.0 prior to 8.0 HF4 and Suite 7.6 prior to 7.6 HF7, Symantec Ghost Solution Suite 3.1 prior to 3.1 MP4, Symantec Endpoint Virtualization 7.x prior to 7.6 HF7, and Symantec Encryption Desktop 10.x… | |
| Modificada | Alta (7.8) | 2.5% | — | Artifex GhostscriptFedoraproject Fedora | 27/11/2019 | 17/6/2026 | A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or… | |
| Modificada | Alta (7.8) | 2.3% | — | Artifex GhostscriptRedhat 3scale API ManagementRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+5 | 27/11/2019 | 17/6/2026 | In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and access files outside of restricted areas. | |
| Modificada | Alta (8.8) | 3.4% | — | Artifex GhostscriptFedoraproject FedoraOpensuse Leap | 15/11/2019 | 17/6/2026 | A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges… | |
| Modificada | Media (6.5) | 1.5% | — | Ghost | 17/9/2019 | 17/6/2026 | The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of exported data. | |
| Modificada | Crítica (9.8) | 11% | — | Artifex GhostscriptRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+8 | 6/9/2019 | 17/6/2026 | A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute… | |
| Modificada | Alta (7.8) | 2.0% | — | Artifex GhostscriptRedhat Openshift Container PlatformOpensuse LeapFedoraproject Fedora+1 | 3/9/2019 | 17/6/2026 | A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or… | |
| Modificada | Alta (7.8) | 3.7% | 💥 PoC | Artifex GhostscriptRedhat Openshift Container PlatformFedoraproject FedoraOpensuse Leap+1 | 3/9/2019 | 17/6/2026 | A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or… |