Ghostscript

Vendor:

First CVE: Mar 21, 2017 · Active for 9 years

129
Total CVEs
More Total CVEs than 99% of tracked products
16.1
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.8%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Ghostscript over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 21, 2017
9 years ago
Most Recent CVE
Sep 22, 2025
305 days ago

CVE Severity & Scoring

Ghostscript129 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local106 (82.2%)
Network22 (17.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (0.8%)
Attack Complexity
Low128 (99.2%)
High1 (0.8%)
Unknown0 (0.0%)
User Interaction
None23 (17.8%)
Unknown0 (0.0%)
Required106 (82.2%)
Privileges Required
Low7 (5.4%)
High0 (0.0%)
None122 (94.6%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (129 CVEs).

129 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps doc
Apr 27, 20177.898YESYES
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers ab
Sep 5, 20187.888NOYES
A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a special
Feb 16, 20229.977NONO
In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.
Mar 21, 20197.859NOYES
The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.
Aug 7, 20178.852NOYES
Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.
Jul 3, 20246.351NOYES
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue exists because of an incom
Oct 15, 20188.643NOYES
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAF
Sep 6, 20199.836NONO
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator.
Oct 19, 20188.635NONO
In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPE
Mar 31, 20239.834NONO

Exploit Exposure

Signals from CVEs in this product scope (129 CVEs).

CISA KEV
1 CVE
0.8% of CVEs· 96th percentile
Metasploit
4 CVEs
3.1% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
3.1% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (129 CVEs).

Media Mentions

Signals from CVEs in this product scope (129 CVEs).

Top CNAs Publishing CVEs For Ghostscript

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.55.015.51.4%00
9.54.019.983.9%00
9.53.319.983.9%00
9.53.019.80.9%00
9.52.119.80.9%00
9.5239.830.0%00
9.5119.80.9%00
9.50126.68.8%00
9.2515.50.4%00
9.2215.51.3%00
9.2157.31.9%00
9.2096.64.7%01
9.1818.823.4%01
9.0717.81.3%00