Vulnerabilities > Artifex > Afpl Ghostscript

DATE CVE VULNERABILITY TITLE RISK
2017-03-07 CVE-2013-5653 Information Exposure vulnerability in multiple products
The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER" argument, which allows remote attackers to read data via a crafted postscript file.
local
low complexity
artifex debian CWE-200
5.5
2017-02-24 CVE-2017-6196 Use After Free vulnerability in Artifex Afpl Ghostscript
Multiple use-after-free vulnerabilities in the gx_image_enum_begin function in base/gxipixel.c in Ghostscript before ecceafe3abba2714ef9b432035fe0739d9b1a283 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PostScript document.
local
low complexity
artifex CWE-416
7.8