Ghostscript
Vendor:
First CVE: Mar 21, 2017 · Active for 9 years
129
Total CVEs
More Total CVEs than 99% of tracked products
16.1
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.8%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Ghostscript over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 21, 2017
9 years ago
Most Recent CVE
Sep 22, 2025
305 days ago
CVE Severity & Scoring
Ghostscript129 CVEs
46%
43%
9%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local106 (82.2%)
Network22 (17.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (0.8%)
Attack Complexity
Low128 (99.2%)
High1 (0.8%)
Unknown0 (0.0%)
User Interaction
None23 (17.8%)
Unknown0 (0.0%)
Required106 (82.2%)
Privileges Required
Low7 (5.4%)
High0 (0.0%)
None122 (94.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (129 CVEs).
129 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-8291HIGH Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps doc | Apr 27, 2017 | 7.8 | 98 | YES | YES |
CVE-2018-16509HIGH An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers ab | Sep 5, 2018 | 7.8 | 88 | NO | YES |
CVE-2021-3781CRITICAL A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a special | Feb 16, 2022 | 9.9 | 77 | NO | NO |
CVE-2019-6116HIGH In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution. | Mar 21, 2019 | 7.8 | 59 | NO | YES |
CVE-2016-7976HIGH The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams. | Aug 7, 2017 | 8.8 | 52 | NO | YES |
CVE-2024-29510MEDIUM Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device. | Jul 3, 2024 | 6.3 | 51 | NO | YES |
CVE-2018-17961HIGH Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue exists because of an incom | Oct 15, 2018 | 8.6 | 43 | NO | YES |
CVE-2019-14813CRITICAL A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAF | Sep 6, 2019 | 9.8 | 36 | NO | NO |
CVE-2018-18284HIGH Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator. | Oct 19, 2018 | 8.6 | 35 | NO | NO |
CVE-2023-28879CRITICAL In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPE | Mar 31, 2023 | 9.8 | 34 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (129 CVEs).
CISA KEV
1 CVE
0.8% of CVEs· 96th percentile
Metasploit
4 CVEs
3.1% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
3.1% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (129 CVEs).
Media Mentions
Signals from CVEs in this product scope (129 CVEs).
Top CNAs Publishing CVEs For Ghostscript
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.55.0 | 1 | 5.5 | 1.4% | 0 | 0 |
| 9.54.0 | 1 | 9.9 | 83.9% | 0 | 0 |
| 9.53.3 | 1 | 9.9 | 83.9% | 0 | 0 |
| 9.53.0 | 1 | 9.8 | 0.9% | 0 | 0 |
| 9.52.1 | 1 | 9.8 | 0.9% | 0 | 0 |
| 9.52 | 3 | 9.8 | 30.0% | 0 | 0 |
| 9.51 | 1 | 9.8 | 0.9% | 0 | 0 |
| 9.50 | 12 | 6.6 | 8.8% | 0 | 0 |
| 9.25 | 1 | 5.5 | 0.4% | 0 | 0 |
| 9.22 | 1 | 5.5 | 1.3% | 0 | 0 |
| 9.21 | 5 | 7.3 | 1.9% | 0 | 0 |
| 9.20 | 9 | 6.6 | 4.7% | 0 | 1 |
| 9.18 | 1 | 8.8 | 23.4% | 0 | 1 |
| 9.07 | 1 | 7.8 | 1.3% | 0 | 0 |