Search CVE reports


Toggle filters

31 – 40 of 243 results


CVE-2024-29507

Medium priority

Some fixes available 1 of 2

Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.

1 affected package

ghostscript

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed Not affected Not affected Not affected
Show less packages

CVE-2024-29509

Medium priority

Some fixes available 2 of 3

Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle.

1 affected package

ghostscript

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed Fixed Not affected Not affected
Show less packages

CVE-2024-29508

Medium priority

Some fixes available 7 of 8

Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.

1 affected package

ghostscript

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-29506

Medium priority

Some fixes available 2 of 3

Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name.

1 affected package

ghostscript

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed Fixed Not affected Not affected
Show less packages

CVE-2024-33871

Medium priority

Some fixes available 6 of 7

An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the Driver...

1 affected package

ghostscript

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed Fixed Fixed Not affected
Show less packages

CVE-2024-33870

Medium priority
Fixed

An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript document) to arbitrary files if the current directory is in the permitted paths. For example, there can be a...

1 affected package

ghostscript

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed Fixed Fixed Not affected
Show less packages

CVE-2024-33869

Medium priority
Fixed

An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a crafted PostScript document) because of path reduction in base/gpmisc.c. For example, restrictions on use of...

1 affected package

ghostscript

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed Fixed Fixed Not affected
Show less packages

CVE-2024-29510

Medium priority
Fixed

Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.

1 affected package

ghostscript

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Fixed Fixed Fixed Not affected
Show less packages

CVE-2023-52722

Medium priority
Fixed

An issue was discovered in Artifex Ghostscript before 10.03.1. psi/zmisc1.c, when SAFER mode is used, allows eexec seeds other than the Type 1 standard.

1 affected package

ghostscript

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ghostscript Not affected Fixed Fixed Not affected
Show less packages

CVE-2024-28757

Medium priority

Some fixes available 2 of 81

libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).

23 affected packages

expat, apache2, apr-util, cmake, ghostscript...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
expat Not affected Fixed Ignored Ignored
apache2 Not affected Not affected Not affected Not affected
apr-util Not affected Not affected Not affected Not affected
cmake Not affected Not affected Not affected Not affected
ghostscript Not affected Not affected Not affected Not affected
texlive-bin Not affected Not affected Not affected Not affected
xmlrpc-c Needs evaluation Needs evaluation Needs evaluation Needs evaluation
vnc4 Not in release Not in release Not in release Needs evaluation
wbxml2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
swish-e Needs evaluation Needs evaluation Needs evaluation Needs evaluation
insighttoolkit4 Not in release Needs evaluation Needs evaluation Needs evaluation
cadaver Needs evaluation Needs evaluation Needs evaluation Needs evaluation
gdcm Not affected Not affected Not affected Needs evaluation
ayttm Not in release Not in release Not in release
cableswig Not in release Not in release Not in release
coin3 Not affected Not affected Not affected Needs evaluation
matanza Ignored Ignored Ignored Ignored
tdom Needs evaluation Needs evaluation Needs evaluation Needs evaluation
vtk Not in release Not in release Not in release
smart Not in release Not in release Not in release Needs evaluation
firefox Not affected Not affected Not in release
thunderbird Not affected Not affected Not in release
libxmltok Ignored Ignored Ignored Ignored
Show all 23 packages Show less packages