CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

artifex

ghostscript

111 known vulnerabilities · sorted by CVSS score

CVE-2021-3781
CRITICAL9.9

A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript interpreter. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

artifex / ghostscript+4
Network
Published Feb 16, 2022
Page 1 of 6
CVE-2025-27832
CRITICAL9.8

An issue was discovered in Artifex Ghostscript before 10.05.0. The NPDL device has a Compression buffer overflow for contrib/japanese/gdevnpdl.c.

artifex / ghostscript
Network
Published Mar 25, 2025
CVE-2025-27831
CRITICAL9.8

An issue was discovered in Artifex Ghostscript before 10.05.0. The DOCXWRITE TXTWRITE device has a text buffer overflow via long characters to devices/vector/doc_common.c.

artifex / ghostscript
Network
Published Mar 25, 2025
CVE-2019-14813
CRITICAL9.8

A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.

artifex / ghostscript+18
Network
Published Sep 6, 2019
CVE-2020-36773
CRITICAL9.8

Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).

artifex / ghostscript+4
Network
Published Feb 4, 2024
CVE-2025-27836
CRITICAL9.8

An issue was discovered in Artifex Ghostscript before 10.05.0. The BJ10V device has a Print buffer overflow in contrib/japanese/gdev10v.c.

artifex / ghostscript
Network
Published Mar 25, 2025
CVE-2025-27837
CRITICAL9.8

An issue was discovered in Artifex Ghostscript before 10.05.0. Access to arbitrary files can occur through a truncated path with invalid UTF-8 characters, for base/gp_mswin.c and base/winrtsup.cpp.

artifex / ghostscript
Network
Published Mar 25, 2025
CVE-2023-28879
CRITICAL9.8

In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.

artifex / ghostscript+2
Network
Published Mar 31, 2023
CVE-2020-15900
CRITICAL9.8

A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and could underflow to max uint32_t. This was fixed in commit 5d499272b95a6b890a1397e11d20937de000d31b.

artifex / ghostscript+4
Network
Published Jul 28, 2020
CVE-2018-19409
CRITICAL9.8

An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device is used.

artifex / ghostscript+11
Network
Published Nov 21, 2018
CVE-2024-29506
HIGH8.8

Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name.

artifex / ghostscript
Network
Published Jul 3, 2024
CVE-2024-33871
HIGH8.8

An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the Driver parameter for opvp (and oprp) devices can have an arbitrary name for a dynamic library; this library is then loaded.

artifex / ghostscript
Network
Published Jul 3, 2024
CVE-2024-29509
HIGH8.8

Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle.

artifex / ghostscript
Network
Published Jul 3, 2024
CVE-2023-43115
HIGH8.8

In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated. NOTE: it is a documented risk that the IJS server can be specified on a gs command line (the IJS device inherently must execute a command to start the IJS server).

artifex / ghostscript+2
Network
Published Sep 18, 2023
CVE-2019-14869
HIGH8.8

A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges within the Ghostscript and access files outside of restricted areas or execute commands.

artifex / ghostscript+5
Network
Published Nov 15, 2019
CVE-2018-17961
HIGH8.6

Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue exists because of an incomplete fix for CVE-2018-17183.

artifex / ghostscript+12
Local
Published Oct 15, 2018
CVE-2018-18284
HIGH8.6

Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator.

artifex / ghostscript+16
Local
Published Oct 19, 2018
CVE-2019-14812
HIGH7.8

A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.

artifex / ghostscript+1
Local
Published Nov 27, 2019
CVE-2018-16543
HIGH7.8

In Artifex Ghostscript before 9.24, gssetresolution and gsgetresolution allow attackers to have an unspecified impact.

artifex / ghostscript+5
Local
Published Sep 5, 2018
CVE-2018-17183
HIGH7.8

Artifex Ghostscript before 9.25 allowed a user-writable error exception table, which could be used by remote attackers able to supply crafted PostScript to potentially overwrite or replace error handlers to inject code.

artifex / ghostscript+10
Local
Published Sep 19, 2018