Aladdin Enterprises' vulnerability footprint centers on Ghostscript, a widely embedded PostScript and PDF rendering engine deployed across print systems, document processing pipelines, and server applications. The durable signal reflects the product's file-parsing role, with recurring weaknesses in improper link resolution and file-access handling that present path-traversal and arbitrary-file-read risks in contexts where untrusted documents are processed. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aladdin Enterprises over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0363HIGH ghostscript before 6.53 allows attackers to execute arbitrary commands by using .locksafe or .setsafe to reset the current pagedevice. | May 29, 2002 | 7.5 | 20 | NO | NO |
CVE-1999-0155HIGH The ghostscript command with the -dSAFER option allows remote attackers to execute commands. | Aug 31, 1995 | 7.5 | 20 | NO | NO |
CVE-2004-0967HIGH The (1) pj-gs.sh, (2) ps2epsi, (3) pv.sh, and (4) sysvlp.sh scripts in the ESP Ghostscript (espgs) package in Trustix Secure Linux 1.5 through 2.1, and other operating systems, all | Feb 9, 2005 | 7.2 | 18 | NO | NO |
CVE-2000-1163MEDIUM ghostscript before 5.10-16 uses an empty LD_RUN_PATH environmental variable to find libraries in the current directory, which could allow local users to execute commands as other u | Jan 9, 2001 | 4.6 | 14 | NO | NO |
ghostscript before 5.10-16 allows local users to overwrite files of other users via a symlink attack. | Jan 9, 2001 | 3.7 | 13 | NO | NO |
ghostscript before 6.51 allows local users to read and write arbitrary files as the 'lp' user via the file operator, even with -dSAFER enabled. | Sep 18, 2001 | 2.6 | 12 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aladdin Enterprises.
Media articles that mention a CVE ID that affects a product developed by Aladdin Enterprises — matched by CVE ID, not by vendor name.