« Back to list

Ghostscript

Ghostscript: vulnerabilities and CVEs

Ghostscript has 13 published vulnerabilities, 3 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs13
Last 12 months3
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-19547High (7)0.16%—Sep 29, 2026
Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource file hijacking. Due to the application searching for PostScript resource files in predictable paths under C:\\gs\\ that do…
CVE-2026-81180High (8.8)0.66%—Sep 18, 2026
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing…
CVE-2026-39919Critical (9.3)0.55%—Sep 15, 2026
Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF…
CVE-2010-4820Medium (4.4)0.47%—Oct 27, 2014
Untrusted search path vulnerability in Ghostscript 8.62 allows local users to execute arbitrary PostScript code via a Trojan horse Postscript library file in Encoding/ under the current working directory, a different…
CVE-2012-4405Medium (6.8)7.5%—Sep 18, 2012
Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to…
CVE-2009-4270High (9.3)6.9%—Dec 21, 2009
Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghostscript 8.64 through 8.70 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF…
CVE-2009-0196High (9.3)7.4%—Apr 16, 2009
Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute…
CVE-2009-0792High (9.3)4.0%—Apr 14, 2009
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow…
CVE-2008-6679Medium (5)4.5%—Apr 8, 2009
Buffer overflow in the BaseFont writer module in Ghostscript 8.62, and possibly other versions, allows remote attackers to cause a denial of service (ps2pdf crash) and possibly execute arbitrary code via a crafted…
CVE-2007-6725High (7.5)4.8%—Apr 8, 2009
The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file that triggers…
CVE-2009-0584High (9.3)4.1%—Mar 23, 2009
icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to…
CVE-2009-0583High (9.3)4.7%—Mar 23, 2009
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow…
CVE-2008-0411Medium (6.8)15%—Feb 28, 2008
Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file containing a long Range array in a…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter1
  2. T1059.007 JavaScript1
  3. T1190 Exploit Public-Facing Application1
  4. T1203 Exploitation for Client Execution1
  5. T1210 Exploitation of Remote Services1
  6. T1574.007 Path Interception by PATH Environment Variable1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.