Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2633▼ 296 respecto a la semana anterior
Críticas / altas1350▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)61▼ 466 respecto a la semana anterior
170 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.6% | — | Artifex Afpl GhostscriptArtifex Ghostscript FontsArtifex GPL Ghostscript | 23/10/2010 | 16/6/2026 | The gs_type2_interpret function in Ghostscript allows remote attackers to cause a denial of service (incorrect pointer dereference and application crash) via crafted font data in a compressed data stream, aka bug 691043. | |
| Modificada | Alta (9.3) | 6.8% | — | Artifex Afpl GhostscriptArtifex Ghostscript FontsArtifex GPL Ghostscript | 26/8/2010 | 16/6/2026 | Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer… | |
| Modificada | Alta (7.2) | 0.51% | — | Artifex Afpl GhostscriptArtifex Ghostscript FontsArtifex GPL Ghostscript | 22/7/2010 | 16/6/2026 | Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program, as demonstrated using gs_init.ps, a different vulnerability than… | |
| Modificada | Alta (9.3) | 6.6% | — | Artifex Afpl GhostscriptArtifex Ghostscript FontsArtifex GPL Ghostscript | 22/7/2010 | 16/6/2026 | Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document containing a long name. | |
| Modificada | Alta (9.3) | 4.0% | — | Artifex GPL Ghostscript | 19/5/2010 | 16/6/2026 | Ghostscript 8.64, 8.70, and possibly other versions allows context-dependent attackers to execute arbitrary code via a PostScript file containing unlimited recursive procedure invocations, which trigger memory corruption in the stack of the interpreter. | |
| Modificada | Alta (9.3) | 9.2% | — | Artifex GPL Ghostscript | 12/5/2010 | 16/6/2026 | Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a crafted PostScript file. | |
| Modificada | Alta (9.3) | 6.9% | — | Ghostscript | 21/12/2009 | 16/6/2026 | Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghostscript 8.64 through 8.70 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file, as originally reported for debug logging code in gdevcups.c in the CUPS output driver. | |
| Modificada | Alta (9.3) | 7.4% | — | Ghostscript | 16/4/2009 | 16/6/2026 | Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute arbitrary code via a PDF file with a JBIG2 symbol dictionary segment with a large run length value. | |
| Modificada | Alta (9.3) | 4.0% | — | GhostscriptArgyllcms | 14/4/2009 | 16/6/2026 | Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application… | |
| Modificada | Media (5) | 4.5% | — | Ghostscript | 8/4/2009 | 16/6/2026 | Buffer overflow in the BaseFont writer module in Ghostscript 8.62, and possibly other versions, allows remote attackers to cause a denial of service (ps2pdf crash) and possibly execute arbitrary code via a crafted Postscript file. | |
| Modificada | Alta (7.5) | 4.8% | — | Ghostscript | 8/4/2009 | 16/6/2026 | The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file that triggers a buffer underflow in the cf_decode_2d function. | |
| Modificada | Alta (9.3) | 4.1% | — | Argyllcms CMSGhostscript | 23/3/2009 | 16/6/2026 | icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using a device… | |
| Modificada | Alta (9.3) | 4.7% | — | GhostscriptArgyllcms | 23/3/2009 | 16/6/2026 | Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application… | |
| Modificada | Media (6.8) | 15% | — | Ghostscript | 28/2/2008 | 16/6/2026 | Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file containing a long Range array in a .seticcspace operator. | |
| Modificada | Alta (7.2) | 0.47% | — | Aladdin Enterprises Ghostscript | 9/2/2005 | 16/6/2026 | The (1) pj-gs.sh, (2) ps2epsi, (3) pv.sh, and (4) sysvlp.sh scripts in the ESP Ghostscript (espgs) package in Trustix Secure Linux 1.5 through 2.1, and other operating systems, allow local users to overwrite files via a symlink attack on temporary files. | |
| Modificada | Alta (7.5) | 2.1% | — | Aladdin Enterprises Ghostscript | 29/5/2002 | 16/6/2026 | ghostscript before 6.53 allows attackers to execute arbitrary commands by using .locksafe or .setsafe to reset the current pagedevice. | |
| Modificada | Baja (2.6) | 0.32% | — | Aladdin Enterprises Ghostscript | 18/9/2001 | 16/6/2026 | ghostscript before 6.51 allows local users to read and write arbitrary files as the 'lp' user via the file operator, even with -dSAFER enabled. | |
| Modificada | Media (4.6) | 0.40% | — | Aladdin Enterprises Ghostscript | 9/1/2001 | 16/6/2026 | ghostscript before 5.10-16 uses an empty LD_RUN_PATH environmental variable to find libraries in the current directory, which could allow local users to execute commands as other users by placing a Trojan horse library into a directory from which another user executes ghostscript. | |
| Modificada | Baja (3.7) | 0.32% | — | Aladdin Enterprises Ghostscript | 9/1/2001 | 16/6/2026 | ghostscript before 5.10-16 allows local users to overwrite files of other users via a symlink attack. | |
| Modificada | Alta (7.5) | 2.8% | — | Aladdin Enterprises Ghostscript | 31/8/1995 | 16/6/2026 | The ghostscript command with the -dSAFER option allows remote attackers to execute commands. |