Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2633▼ 296 respecto a la semana anterior
Críticas / altas1350▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)61▼ 466 respecto a la semana anterior
–

170 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)2.6%—Artifex Afpl GhostscriptArtifex Ghostscript FontsArtifex GPL Ghostscript23/10/201016/6/2026
The gs_type2_interpret function in Ghostscript allows remote attackers to cause a denial of service (incorrect pointer dereference and application crash) via crafted font data in a compressed data stream, aka bug 691043.
ModificadaAlta (9.3)6.8%—Artifex Afpl GhostscriptArtifex Ghostscript FontsArtifex GPL Ghostscript26/8/201016/6/2026
Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer…
ModificadaAlta (7.2)0.51%—Artifex Afpl GhostscriptArtifex Ghostscript FontsArtifex GPL Ghostscript22/7/201016/6/2026
Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program, as demonstrated using gs_init.ps, a different vulnerability than…
ModificadaAlta (9.3)6.6%—Artifex Afpl GhostscriptArtifex Ghostscript FontsArtifex GPL Ghostscript22/7/201016/6/2026
Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document containing a long name.
ModificadaAlta (9.3)4.0%—Artifex GPL Ghostscript19/5/201016/6/2026
Ghostscript 8.64, 8.70, and possibly other versions allows context-dependent attackers to execute arbitrary code via a PostScript file containing unlimited recursive procedure invocations, which trigger memory corruption in the stack of the interpreter.
ModificadaAlta (9.3)9.2%—Artifex GPL Ghostscript12/5/201016/6/2026
Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a crafted PostScript file.
ModificadaAlta (9.3)6.9%—Ghostscript21/12/200916/6/2026
Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghostscript 8.64 through 8.70 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file, as originally reported for debug logging code in gdevcups.c in the CUPS output driver.
ModificadaAlta (9.3)7.4%—Ghostscript16/4/200916/6/2026
Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute arbitrary code via a PDF file with a JBIG2 symbol dictionary segment with a large run length value.
ModificadaAlta (9.3)4.0%—GhostscriptArgyllcms14/4/200916/6/2026
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application…
ModificadaMedia (5)4.5%—Ghostscript8/4/200916/6/2026
Buffer overflow in the BaseFont writer module in Ghostscript 8.62, and possibly other versions, allows remote attackers to cause a denial of service (ps2pdf crash) and possibly execute arbitrary code via a crafted Postscript file.
ModificadaAlta (7.5)4.8%—Ghostscript8/4/200916/6/2026
The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file that triggers a buffer underflow in the cf_decode_2d function.
ModificadaAlta (9.3)4.1%—Argyllcms CMSGhostscript23/3/200916/6/2026
icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using a device…
ModificadaAlta (9.3)4.7%—GhostscriptArgyllcms23/3/200916/6/2026
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application…
ModificadaMedia (6.8)15%—Ghostscript28/2/200816/6/2026
Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file containing a long Range array in a .seticcspace operator.
ModificadaAlta (7.2)0.47%—Aladdin Enterprises Ghostscript9/2/200516/6/2026
The (1) pj-gs.sh, (2) ps2epsi, (3) pv.sh, and (4) sysvlp.sh scripts in the ESP Ghostscript (espgs) package in Trustix Secure Linux 1.5 through 2.1, and other operating systems, allow local users to overwrite files via a symlink attack on temporary files.
ModificadaAlta (7.5)2.1%—Aladdin Enterprises Ghostscript29/5/200216/6/2026
ghostscript before 6.53 allows attackers to execute arbitrary commands by using .locksafe or .setsafe to reset the current pagedevice.
ModificadaBaja (2.6)0.32%—Aladdin Enterprises Ghostscript18/9/200116/6/2026
ghostscript before 6.51 allows local users to read and write arbitrary files as the 'lp' user via the file operator, even with -dSAFER enabled.
ModificadaMedia (4.6)0.40%—Aladdin Enterprises Ghostscript9/1/200116/6/2026
ghostscript before 5.10-16 uses an empty LD_RUN_PATH environmental variable to find libraries in the current directory, which could allow local users to execute commands as other users by placing a Trojan horse library into a directory from which another user executes ghostscript.
ModificadaBaja (3.7)0.32%—Aladdin Enterprises Ghostscript9/1/200116/6/2026
ghostscript before 5.10-16 allows local users to overwrite files of other users via a symlink attack.
ModificadaAlta (7.5)2.8%—Aladdin Enterprises Ghostscript31/8/199516/6/2026
The ghostscript command with the -dSAFER option allows remote attackers to execute commands.