Vulnerabilities > Artifex > High

DATE CVE VULNERABILITY TITLE RISK
2023-12-26 CVE-2023-51104 Divide By Zero vulnerability in Artifex Mupdf 1.23.4
A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function pnm_binary_read_image() of load-pnm.c when span equals zero.
network
low complexity
artifex CWE-369
7.5
2023-12-26 CVE-2023-51105 Divide By Zero vulnerability in Artifex Mupdf 1.23.4
A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function bmp_decompress_rle4() of load-bmp.c.
network
low complexity
artifex CWE-369
7.5
2023-12-26 CVE-2023-51106 Divide By Zero vulnerability in Artifex Mupdf 1.23.4
A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in function pnm_binary_read_image() of load-pnm.c when fz_colorspace_n returns zero.
network
low complexity
artifex CWE-369
7.5
2023-12-26 CVE-2023-51107 Divide By Zero vulnerability in Artifex Mupdf 1.23.4
A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in functon compute_color() of jquant2.c.
network
low complexity
artifex CWE-369
7.5
2023-12-06 CVE-2023-46751 Use After Free vulnerability in Artifex Ghostscript
An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10.02.0 allows remote attackers to crash the application via a dangling pointer.
network
low complexity
artifex CWE-416
7.5
2023-09-18 CVE-2023-43115 In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated.
network
low complexity
artifex fedoraproject
8.8
2023-08-22 CVE-2020-21890 Out-of-bounds Write vulnerability in Artifex Ghostscript 9.50
Buffer Overflow vulnerability in clj_media_size function in devices/gdevclj.c in Artifex Ghostscript 9.50 allows remote attackers to cause a denial of service or other unspecified impact(s) via opening of crafted PDF document.
local
low complexity
artifex CWE-787
7.8
2023-07-07 CVE-2021-33796 Use After Free vulnerability in Artifex Mujs
In MuJS before version 1.1.2, a use-after-free flaw in the regexp source property access may cause denial of service.
network
low complexity
artifex CWE-416
7.5
2023-06-25 CVE-2023-36664 Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
local
low complexity
artifex debian fedoraproject
7.8
2022-11-23 CVE-2022-44789 Out-of-bounds Write vulnerability in multiple products
A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file.
network
low complexity
artifex debian fedoraproject CWE-787
8.8