Artifex Software maintains a narrowly focused portfolio centered on document-processing and rendering tools such as Ghostscript and MuPDF that are deeply embedded across a broad range of server, printing, and content-management infrastructure despite limited product count. The vendor's vulnerability footprint is disproportionately large within the landscape, reflecting the complexity of parsing untrusted document formats and the memory-safety demands of C-based codebases; a meaningful share of disclosures reach serious severity, and vulnerabilities in this space have an established tendency to acquire public exploit code. The exposure recurs consistently across weakness classes including out-of-bounds writes, buffer overflows, use-after-free conditions, and out-of-bounds reads, reflecting the inherent challenges of safe memory management in document parsing engines that process diverse and potentially malicious input. Defenders should treat Artifex advisories as broadly applicable given the ubiquity of Ghostscript in legacy printing and document-processing pipelines, and should prioritize patching where these tools remain internet-exposed or process untrusted documents. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Artifex over time
Signals from CVEs in this vendor scope (258 CVEs).
258 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-8291HIGH Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps doc | Apr 27, 2017 | 7.8 | 98 | YES | YES |
CVE-2018-16509HIGH An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers ab | Sep 5, 2018 | 7.8 | 88 | NO | YES |
CVE-2021-3781CRITICAL A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a special | Feb 16, 2022 | 9.9 | 77 | NO | NO |
CVE-2019-6116HIGH In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution. | Mar 21, 2019 | 7.8 | 59 | NO | YES |
CVE-2016-7976HIGH The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams. | Aug 7, 2017 | 8.8 | 52 | NO | YES |
CVE-2024-29510MEDIUM Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device. | Jul 3, 2024 | 6.3 | 51 | NO | YES |
CVE-2021-3407MEDIUM A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences. | Feb 23, 2021 | 5.5 | 45 | NO | NO |
CVE-2010-1869HIGH Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a crafted PostScript file. | May 12, 2010 | 9.3 | 45 | NO | YES |
CVE-2018-17961HIGH Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue exists because of an incom | Oct 15, 2018 | 8.6 | 43 | NO | YES |
CVE-2014-2013HIGH Stack-based buffer overflow in the xps_parse_color function in xps/xps-common.c in MuPDF 1.3 and earlier allows remote attackers to execute arbitrary code via a large number of ent | Mar 3, 2014 | 7.5 | 43 | NO | YES |
Signals from CVEs in this vendor scope (258 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Artifex.
Media articles that mention a CVE ID that affects a product developed by Artifex — matched by CVE ID, not by vendor name.