Artifex GPL Ghostscript 9.21

CPE Details

Artifex GPL Ghostscript 9.21
9.21
2020-01-29
15h46 +00:00
2020-01-29
15h46 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:artifex:gpl_ghostscript:9.21:*:*:*:*:*:*:*

Informations

Vendor

artifex

Product

gpl_ghostscript

Version

9.21

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2018-18284 2018-10-19 20h00 +00:00 Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator.
8.6
High
CVE-2018-16513 2018-09-05 11h00 +00:00 In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the setcolor function to crash the interpreter or possibly have unspecified other impact.
7.8
High
CVE-2018-16509 2018-09-05 04h00 +00:00 An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction.
7.8
High
CVE-2018-16510 2018-09-05 04h00 +00:00 An issue was discovered in Artifex Ghostscript before 9.24. Incorrect exec stack handling in the "CS" and "SC" PDF primitives could be used by remote attackers able to supply crafted PDFs to crash the interpreter or possibly have unspecified other impact.
7.8
High
CVE-2018-15911 2018-08-28 02h00 +00:00 In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode operator to crash the interpreter or potentially execute code.
7.8
High
CVE-2018-15909 2018-08-27 15h00 +00:00 In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScript files to crash the interpreter or potentially execute code.
7.8
High
CVE-2018-15910 2018-08-27 15h00 +00:00 In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the LockDistillerParams parameter to crash the interpreter or execute code.
7.8
High