📦 Ghostscript

by Artifex

🔍 What is Ghostscript?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-27836

CRITICAL CVSS 9.8 Mar 25, 2025

A buffer overflow vulnerability in the BJ10V device driver in Ghostscript allows attackers to execute arbitrary code or cause denial of service. This affects systems using Ghostscript for processing P...

CVE-2025-27831

CRITICAL CVSS 9.8 Mar 25, 2025

A buffer overflow vulnerability in Artifex Ghostscript's DOCXWRITE/TXTWRITE device allows attackers to execute arbitrary code or cause denial of service by processing specially crafted documents. This...

CVE-2020-36773

CRITICAL CVSS 9.8 Feb 4, 2024

This vulnerability in Ghostscript allows attackers to execute arbitrary code or cause denial of service by exploiting out-of-bounds write and use-after-free flaws in the txtwrite device. It affects sy...

CVE-2023-28879

CRITICAL CVSS 9.8 Mar 31, 2023

This CVE describes a buffer overflow vulnerability in Artifex Ghostscript's PostScript interpreter that could allow attackers to corrupt internal data structures. If exploited, it could potentially le...

CVE-2025-27835

HIGH CVSS 7.8 Mar 25, 2025

A buffer overflow vulnerability in Artifex Ghostscript's glyph-to-Unicode conversion function allows attackers to execute arbitrary code or cause denial of service. This affects systems processing unt...

CVE-2025-27830

HIGH CVSS 7.8 Mar 25, 2025

A buffer overflow vulnerability in Artifex Ghostscript allows attackers to execute arbitrary code or cause denial of service by processing maliciously crafted font files. This affects systems using Gh...

CVE-2025-27833

HIGH CVSS 7.8 Mar 25, 2025

A buffer overflow vulnerability in Artifex Ghostscript allows attackers to execute arbitrary code by providing a specially crafted long TTF font name. This affects systems processing PDF files with Gh...

CVE-2025-27834

HIGH CVSS 7.8 Mar 25, 2025

A buffer overflow vulnerability in Artifex Ghostscript allows remote attackers to execute arbitrary code by crafting a malicious PDF document with an oversized Type 4 function. This affects systems pr...

CVE-2024-46952

HIGH CVSS 7.8 Nov 10, 2024

This vulnerability in Artifex Ghostscript allows buffer overflow during PDF XRef stream handling, potentially enabling remote code execution. It affects systems processing PDF files with Ghostscript v...

CVE-2024-46954

HIGH CVSS 7.8 Nov 10, 2024

A directory traversal vulnerability in Ghostscript's UTF-8 decoder allows attackers to escape directory restrictions via specially crafted overlong UTF-8 sequences. This affects systems processing unt...

CVE-2024-46956

HIGH CVSS 7.8 Nov 10, 2024

This vulnerability in Ghostscript allows out-of-bounds memory access in the filenameforall function, which could lead to arbitrary code execution. It affects systems running Ghostscript before version...

CVE-2024-29511

HIGH CVSS 7.5 Jul 3, 2024

This vulnerability in Ghostscript with Tesseract OCR allows attackers to read arbitrary files and write error messages to arbitrary locations via directory traversal in OCRLanguage parameters. Systems...

CVE-2024-33871

HIGH CVSS 8.8 Jul 3, 2024

This vulnerability in Ghostscript allows arbitrary code execution by loading a malicious dynamic library specified in a crafted PostScript document. It affects systems running Ghostscript versions bef...

CVE-2024-29506

HIGH CVSS 8.8 Jul 3, 2024

This vulnerability is a stack-based buffer overflow in Artifex Ghostscript's pdfi_apply_filter() function that can be triggered by a malicious PDF file with an overly long filter name. Attackers could...

CVE-2024-29509

HIGH CVSS 8.8 Jul 3, 2024

This vulnerability in Artifex Ghostscript allows heap-based buffer overflow when processing PDF passwords containing null bytes. Attackers could potentially execute arbitrary code or cause denial of s...

CVE-2023-46751

HIGH CVSS 7.5 Dec 6, 2023

A use-after-free vulnerability in Ghostscript's gdev_prn_open_printer_seekable() function allows remote attackers to crash the application via a dangling pointer. This affects all systems running vuln...

CVE-2023-43115

HIGH CVSS 8.8 Sep 18, 2023

This vulnerability in Artifex Ghostscript allows remote code execution via specially crafted PostScript documents. Attackers can bypass SAFER restrictions by switching to the IJS device or modifying I...

CVE-2023-36664

HIGH CVSS 7.8 Jun 25, 2023

CVE-2023-36664 is a security bypass vulnerability in Artifex Ghostscript that allows arbitrary command execution through improper permission validation for pipe devices. Attackers can exploit this by ...

CVE-2019-25059

HIGH CVSS 7.8 Apr 25, 2022

Artifex Ghostscript through version 9.26 contains a vulnerability in its .completefont handling that could allow arbitrary code execution. This affects systems using Ghostscript for PDF/PostScript pro...

CVE-2025-59799

MEDIUM CVSS 4.3 Sep 22, 2025

This CVE describes a stack-based buffer overflow vulnerability in Artifex Ghostscript's PDF processing component. Attackers could exploit this by providing a specially crafted PDF with a large size va...

CVE-2025-59800

MEDIUM CVSS 4.3 Sep 22, 2025

This CVE describes an integer overflow vulnerability in Artifex Ghostscript's PDF OCR device that leads to heap-based buffer overflow when processing certain PDF files. Attackers could potentially exe...

CVE-2025-48708

MEDIUM CVSS 4.0 May 23, 2025

This vulnerability in Artifex Ghostscript allows PDF passwords to be exposed in cleartext when processing certain PDF documents. It affects systems using vulnerable Ghostscript versions to process PDF...

CVE-2025-46646

MEDIUM CVSS 4.5 Apr 26, 2025

This vulnerability in Artifex Ghostscript involves improper handling of overlong UTF-8 encoding in the decode_utf8 function, which could allow attackers to cause denial of service or potentially execu...

CVE-2024-29507

MEDIUM CVSS 5.4 Jul 3, 2024

This CVE describes a stack-based buffer overflow vulnerability in Artifex Ghostscript when processing CIDFSubstPath and CIDFSubstFont parameters. Attackers could potentially execute arbitrary code or ...

CVE-2024-33870

MEDIUM CVSS 6.3 Jul 3, 2024

This vulnerability in Ghostscript allows path traversal attacks via crafted PostScript documents, enabling unauthorized file access when the current directory is in permitted paths. It affects systems...