Записи ghostscript
10 опубликованных записей вендора ghostscript.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 9
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer6
- CWE-189 Numeric Errors3
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2009-0196Эксплойта нет | Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscghostscript · ghostscript · CWE-119 | Критическая9,3 | — | 7,4 % | 16 апр. 2009 г. |
39Наблюдать | CVE-2009-4270Эксплойта нет | Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghostscript 8.64 through 8.70 allows remote attackers to cause a dghostscript · ghostscript · CWE-119 | Критическая9,3 | — | 6,9 % | 21 дек. 2009 г. |
38Наблюдать | CVE-2009-0583Эксплойта нет | Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 andghostscript · ghostscript · CWE-119 | Критическая9,3 | — | 4,7 % | 23 мар. 2009 г. |
38Наблюдать | CVE-2009-0584Эксплойта нет | icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Managhostscript · ghostscript · CWE-189 | Критическая9,3 | — | 4,1 % | 23 мар. 2009 г. |
38Наблюдать | CVE-2009-0792Эксплойта нет | Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 andghostscript · ghostscript · CWE-189 | Критическая9,3 | — | 4,0 % | 14 апр. 2009 г. |
31Наблюдать | CVE-2008-0411Proof of concept | Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrghostscript · ghostscript · CWE-119 | Средняя6,8 | — | 14,5 % | 28 февр. 2008 г. |
31Наблюдать | CVE-2007-6725Эксплойта нет | The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and possibly other versions, allows remote attackers to cause a denial of service (cghostscript · ghostscript · CWE-119 | Высокая7,5 | — | 4,8 % | 8 апр. 2009 г. |
29Наблюдать | CVE-2012-4405Эксплойта нет | Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghoscolor · icclib · CWE-189 | Средняя6,8 | — | 7,5 % | 18 сент. 2012 г. |
21Наблюдать | CVE-2008-6679Эксплойта нет | Buffer overflow in the BaseFont writer module in Ghostscript 8.62, and possibly other versions, allows remote attackers to cause a denial ofghostscript · ghostscript · CWE-119 | Средняя5,0 | — | 4,5 % | 8 апр. 2009 г. |
17Наблюдать | CVE-2010-4820Эксплойта нет | Untrusted search path vulnerability in Ghostscript 8.62 allows local users to execute arbitrary PostScript code via a Trojan horse Postscripghostscript · ghostscript · CWE-94 | Средняя4,4 | — | 0,5 % | 26 окт. 2014 г. |
- CVE-2009-019639Наблюдать
Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostsc
КритическаяCVSS 9,3Эксплойта нетEPSS 7 %ghostscript · ghostscript16 апр. 2009 г.
- CVE-2009-427039Наблюдать
Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghostscript 8.64 through 8.70 allows remote attackers to cause a d
КритическаяCVSS 9,3Эксплойта нетEPSS 7 %ghostscript · ghostscript21 дек. 2009 г.
- CVE-2009-058338Наблюдать
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and
КритическаяCVSS 9,3Эксплойта нетEPSS 5 %ghostscript · ghostscript23 мар. 2009 г.
- CVE-2009-058438Наблюдать
icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Mana
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %ghostscript · ghostscript23 мар. 2009 г.
- CVE-2009-079238Наблюдать
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %ghostscript · ghostscript14 апр. 2009 г.
- CVE-2008-041131Наблюдать
Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitr
СредняяCVSS 6,8Proof of conceptEPSS 15 %ghostscript · ghostscript28 февр. 2008 г.
- CVE-2007-672531Наблюдать
The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and possibly other versions, allows remote attackers to cause a denial of service (c
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %ghostscript · ghostscript8 апр. 2009 г.
- CVE-2012-440529Наблюдать
Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghos
СредняяCVSS 6,8Эксплойта нетEPSS 7 %color · icclib18 сент. 2012 г.
- CVE-2008-667921Наблюдать
Buffer overflow in the BaseFont writer module in Ghostscript 8.62, and possibly other versions, allows remote attackers to cause a denial of
СредняяCVSS 5,0Эксплойта нетEPSS 4 %ghostscript · ghostscript8 апр. 2009 г.
- CVE-2010-482017Наблюдать
Untrusted search path vulnerability in Ghostscript 8.62 allows local users to execute arbitrary PostScript code via a Trojan horse Postscrip
СредняяCVSS 4,4Эксплойта нетEPSS 0 %ghostscript · ghostscript26 окт. 2014 г.