Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

367 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)1.3%—Artifex Ghostscript23/5/201917/6/2026
Artifex Ghostscript 9.22 is affected by: Obtain Information. The impact is: obtain sensitive information. The component is: affected source code file, affected function, affected executable, affected libga (imagemagick used that). The attack vector is: Someone must open a postscript file though ghostscript. Because of…
ModificadaAlta (7.8)1.8%—Artifex GhostscriptDebian LinuxOpensuse LeapFedoraproject Fedora+216/5/201917/6/2026
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27…
ModificadaMedia (5.5)2.5%—Artifex GhostscriptRedhat Ansible TowerRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+825/3/201917/6/2026
It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.
ModificadaMedia (5.5)2.5%—Artifex GhostscriptRedhat Ansible TowerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+725/3/201917/6/2026
It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.
ModificadaAlta (7.8)42%💥 ExploitArtifex GhostscriptFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+721/3/201917/6/2026
In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.
ModificadaAlta (7.3)0.87%—Symantec Ghost Solution Suite8/2/201917/6/2026
Symantec Ghost Solution Suite (GSS) versions prior to 3.3 RU1 may be susceptible to a DLL hijacking vulnerability, which is a type of issue whereby a potential attacker attempts to execute unexpected code on your machine. This occurs via placement of a potentially foreign file (DLL) that the attacker then attempts to…
ModificadaMedia (5.5)1.9%—Artifex GhostscriptDebian Linux2/1/201917/6/2026
In Artifex Ghostscript before 9.26, a carefully crafted PDF file can trigger an extremely long running computation when parsing the file.
ModificadaAlta (7.8)2.9%—Artifex GhostscriptDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+320/12/201817/6/2026
In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscript process. This is a type confusion issue because of failure to…
ModificadaAlta (7.8)1.2%—Artifex GhostscriptRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+33/12/201817/6/2026
It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSAFER protection to, for example, execute arbitrary shell commands via a specially crafted PostScript document. This only affects ghostscript 9.07 as shipped with Red Hat…
ModificadaAlta (7.8)3.0%—Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Openshift Container Platform+623/11/201817/6/2026
psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a JBIG2Decode type confusion.
ModificadaAlta (7.8)3.0%—Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Openshift Container Platform+623/11/201817/6/2026
psi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a setcolorspace type confusion.
ModificadaAlta (7.8)9.5%—Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Openshift Container Platform+623/11/201817/6/2026
psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same.
ModificadaCrítica (9.8)7.8%—Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+421/11/201817/6/2026
An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device is used.
ModificadaAlta (8.6)16%—Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxArtifex GPL Ghostscript+719/10/201817/6/2026
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator.
ModificadaMedia (6.3)2.7%—Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+515/10/201817/6/2026
Artifex Ghostscript allows attackers to bypass a sandbox protection mechanism by leveraging exposure of system operators in the saved execution stack in an error object.
ModificadaAlta (8.6)10.0%💥 ExploitArtifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+515/10/201817/6/2026
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue exists because of an incomplete fix for CVE-2018-17183.
ModificadaAlta (7.8)1.8%—Artifex GhostscriptCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux Desktop+519/9/201817/6/2026
Artifex Ghostscript before 9.25 allowed a user-writable error exception table, which could be used by remote attackers able to supply crafted PostScript to potentially overwrite or replace error handlers to inject code.
ModificadaAlta (7.8)2.2%—Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+510/9/201817/6/2026
An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" checking when running out of stack during exception handling could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction. This is due to an incomplete fix for CVE-2018-16509.
ModificadaAlta (7.8)1.7%—Artifex GhostscriptCanonical Ubuntu LinuxDebian Linux6/9/201817/6/2026
An issue was discovered in Artifex Ghostscript before 9.24. The .setdistillerkeys PostScript command is accepted even though it is not intended for use during document processing (e.g., after the startup phase). This leads to memory corruption, allowing remote attackers able to supply crafted PostScript to crash the…
ModificadaAlta (7.8)1.3%—Artifex GhostscriptCanonical Ubuntu LinuxDebian Linux5/9/201817/6/2026
In Artifex Ghostscript before 9.24, gssetresolution and gsgetresolution allow attackers to have an unspecified impact.
ModificadaMedia (5.5)1.9%—Artifex GhostscriptRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+45/9/201817/6/2026
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use insufficient interpreter stack-size checking during error handling to crash the interpreter.
ModificadaMedia (5.5)1.4%—Artifex GhostscriptCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux Desktop+55/9/201817/6/2026
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect free logic in pagedevice replacement to crash the interpreter.
ModificadaAlta (7.8)1.6%—Artifex GhostscriptRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+75/9/201817/6/2026
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified other impact.
ModificadaMedia (5.5)1.4%—Artifex GhostscriptCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux Desktop+55/9/201817/6/2026
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect access checking in temp file handling to disclose contents of files on the system otherwise not readable.
ModificadaAlta (7.8)1.5%—Artifex GhostscriptCanonical Ubuntu LinuxDebian LinuxArtifex GPL Ghostscript+15/9/201817/6/2026
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the setcolor function to crash the interpreter or possibly have unspecified other impact.