Vulnerability index

Browse CVEs

131 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mupdf MEDIUM 5.5
CVE-2019-6131

svg-run.c in Artifex MuPDF 1.14.0 has infinite recursion with stack consumption in svg_run_use_symbol, svg_run_element, and svg_run_use, as demonstra…

No fix yet
Fix from $1,600 2019-01-11
Mupdf MEDIUM 5.5
CVE-2018-19881

In Artifex MuPDF 1.14.0, svg/svg-run.c allows remote attackers to cause a denial of service (recursive calls followed by a fitz/xml.c fz_xml_att cras…

No fix yet
Fix from $1,600 2018-12-06
Mupdf MEDIUM 5.5
CVE-2018-19882

In Artifex MuPDF 1.14.0, the svg_run_image function in svg/svg-run.c allows remote attackers to cause a denial of service (href_att NULL pointer dere…

No fix yet
Fix from $1,600 2018-12-06
Mupdf MEDIUM 5.5
CVE-2018-18662

There is an out-of-bounds read in fz_run_t3_glyph in fitz/font.c in Artifex MuPDF 1.14.0, as demonstrated by mutool.

No fix yet
Fix from $1,600 2018-10-26
Mupdf MEDIUM 5.5
CVE-2018-16647

In Artifex MuPDF 1.13.0, the pdf_get_xref_entry function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation fault i…

No fix yet
Fix from $1,600 2018-09-06
Mupdf MEDIUM 5.5
CVE-2018-16648

In Artifex MuPDF 1.13.0, the fz_append_byte function in fitz/buffer.c allows remote attackers to cause a denial of service (segmentation fault) via a…

No fix yet
Fix from $1,600 2018-09-06
Ghostscript MEDIUM 5.3
CVE-2018-11645

psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine…

Fix: after 9.20
Fix from $1,600 2018-06-01
Mupdf HIGH 7.8
CVE-2018-1000038

In Artifex MuPDF 1.12.0 and earlier, a stack buffer overflow in function pdf_lookup_cmap_full in pdf/pdf-cmap.c could allow an attacker to execute ar…

Fix: after 1.12.0
Fix from $1,950 2018-05-24
Mupdf MEDIUM 6.3
CVE-2018-1000039

In Artifex MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PDF parser could allow an attacker to execute arbitrary code, read memo…

Fix: after 1.12.0
Fix from $1,600 2018-05-24
Mupdf HIGH 7.8
CVE-2016-8728

An exploitable heap out of bounds write vulnerability exists in the Fitz graphical library part of the MuPDF renderer. A specially crafted PDF file c…

Mitigation only
Fix from $1,950 2018-04-24
Mupdf HIGH 7.8
CVE-2016-8729

An exploitable memory corruption vulnerability exists in the JBIG2 parser of Artifex MuPDF 1.9. A specially crafted PDF can cause a negative number t…

Mitigation only
Fix from $1,950 2018-04-24
Mujs MEDIUM 5.5
CVE-2018-5759EPSS 5%

jsparse.c in Artifex MuJS through 1.0.2 does not properly maintain the AST depth for binary expressions, which allows remote attackers to cause a den…

Fix: after 1.0.2
Fix from $1,600 2018-01-24
Mujs MEDIUM 5.5
CVE-2018-6191EPSS 5%

The js_strtod function in jsdtoa.c in Artifex MuJS through 1.0.2 has an integer overflow because of incorrect exponent validation.

Fix: after 1.0.2
Fix from $1,600 2018-01-24
Mupdf HIGH 7.8
CVE-2017-17858

Heap-based buffer overflow in the ensure_solid_xref function in pdf/pdf-xref.c in Artifex MuPDF 1.12.0 allows a remote attacker to potentially execut…

Patch available
Fix from $1,950 2018-01-22
Mupdf HIGH 7.8
CVE-2017-15587

An integer overflow was discovered in pdf_read_new_xref_section in pdf/pdf-xref.c in Artifex MuPDF 1.11.

Mitigation only
Fix from $1,950 2017-10-18
Mupdf HIGH 7.8
CVE-2017-15369

The build_filter_chain function in pdf/pdf-stream.c in Artifex MuPDF before 2017-09-25 mishandles a certain case where a variable may reside in a reg…

Fix: after 1.11
Fix from $1,950 2017-10-16
Gsview HIGH 7.8
CVE-2017-14945

Artifex GSView 6.0 Beta on Windows allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, r…

No fix yet
Fix from $1,950 2017-09-30
Gsview HIGH 7.8
CVE-2017-14946

Artifex GSView 6.0 Beta on Windows allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, r…

No fix yet
Fix from $1,950 2017-09-30
Gsview HIGH 7.8
CVE-2017-14947

Artifex GSView 6.0 Beta on Windows allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "Rea…

No fix yet
Fix from $1,950 2017-09-30
Mupdf HIGH 7.8
CVE-2017-14685

Artifex MuPDF 1.11 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to "Data …

No fix yet
Fix from $1,950 2017-09-22
Mupdf HIGH 7.8
CVE-2017-14686

Artifex MuPDF 1.11 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "User Mode Write AV …

No fix yet
Fix from $1,950 2017-09-22
Mupdf HIGH 7.8
CVE-2017-14687

Artifex MuPDF 1.11 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to "Data …

No fix yet
Fix from $1,950 2017-09-22
Ghostscript HIGH 8.8
CVE-2016-7976EPSS 23%

The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.

Mitigation only
Fix from $1,950 2017-08-07
Ghostscript Ghostxps HIGH 7.8
CVE-2017-9610

The xps_load_sfnt_name function in xps/xpsfont.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-base…

No fix yet
Fix from $1,950 2017-07-26
Ghostscript Ghostxps HIGH 7.8
CVE-2017-9618

The xps_load_sfnt_name function in xps/xpsfont.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (buffer ov…

No fix yet
Fix from $1,950 2017-07-26
Ghostscript Ghostxps HIGH 7.8
CVE-2017-9619

The xps_true_callback_glyph_name function in xps/xpsttf.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (…

No fix yet
Fix from $1,950 2017-07-26
Ghostscript Ghostxps HIGH 7.8
CVE-2017-9620

The xps_select_font_encoding function in xps/xpsfont.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (hea…

No fix yet
Fix from $1,950 2017-07-26
Ghostscript Ghostxps HIGH 7.8
CVE-2017-9740

The xps_decode_font_char_imp function in xps/xpsfont.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (hea…

No fix yet
Fix from $1,950 2017-07-26
Ghostscript CRITICAL 9.8
CVE-2016-7978EPSS 6%

Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors related to a reference leak in .s…

Patch available
Fix from $2,300 2017-05-23
Ghostscript CRITICAL 9.8
CVE-2016-7979EPSS 6%

Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code by leverag…

Fix: after 9.20
Fix from $2,300 2017-05-23