Ghostscript is a widely embedded PostScript and PDF rendering engine used across document-processing workflows, server applications, and content-management systems, despite its narrow product footprint. The vendor's vulnerability exposure centers on memory-safety and code-injection weaknesses inherent to a complex interpreter handling untrusted document formats, and has a moderate tendency to acquire public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ghostscript over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0411MEDIUM Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file con | Feb 28, 2008 | 6.8 | 33 | NO | YES |
CVE-2009-0196HIGH Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions | Apr 16, 2009 | 9.3 | 30 | NO | NO |
CVE-2009-0792HIGH Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management Sys | Apr 14, 2009 | 9.3 | 30 | NO | NO |
CVE-2009-4270HIGH Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghostscript 8.64 through 8.70 allows remote attackers to cause a denial of service (crash) and possibly ex | Dec 21, 2009 | 9.3 | 29 | NO | NO |
CVE-2009-0583HIGH Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management Sys | Mar 23, 2009 | 9.3 | 27 | NO | NO |
CVE-2012-4405MEDIUM Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management | Sep 18, 2012 | 6.8 | 26 | NO | NO |
CVE-2009-0584HIGH icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, a | Mar 23, 2009 | 9.3 | 24 | NO | NO |
CVE-2007-6725HIGH The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary cod | Apr 8, 2009 | 7.5 | 21 | NO | NO |
CVE-2010-4820MEDIUM Untrusted search path vulnerability in Ghostscript 8.62 allows local users to execute arbitrary PostScript code via a Trojan horse Postscript library file in Encoding/ under the cu | Oct 27, 2014 | 4.4 | 18 | NO | NO |
CVE-2008-6679MEDIUM Buffer overflow in the BaseFont writer module in Ghostscript 8.62, and possibly other versions, allows remote attackers to cause a denial of service (ps2pdf crash) and possibly exe | Apr 8, 2009 | 5.0 | 16 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ghostscript.
Media articles that mention a CVE ID that affects a product developed by Ghostscript — matched by CVE ID, not by vendor name.