Known vulnerabilities in ghostscript (Debian package) 9.20~dfsg-3.2+deb9u4

Vendor: Debian
Version: 9.20~dfsg-3.2+deb9u4
Software CPE: cpe:2.3:o:debian:ghostscript_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 11
Public exploits: 2
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting ghostscript (Debian package) version 9.20~dfsg-3.2+deb9u4 ghostscript (Debian package) 9.20~dfsg-3.2+deb9u4 is affected by 11 vulnerabilities: 4 high, 1 medium, 6 low Critical High Medium Low

Vulnerabilities (11)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU20471 - Permissions, Privileges, and Access Controls
CVE-2019-14817
CWE-264 Low
No
No
9.26a~dfsg-0+deb9u5, 9.27~dfsg-2+deb10u2 29.08.2019 SB2019081208
SB2019083010
SB2019090215
and 10 more
#VU20470 - Permissions, Privileges, and Access Controls
CVE-2019-14813
CWE-264 Low
No
No
9.26a~dfsg-0+deb9u5, 9.27~dfsg-2+deb10u2 29.08.2019 SB2019081208
SB2019083010
SB2019090215
and 10 more
#VU20469 - Permissions, Privileges, and Access Controls
CVE-2019-14812
CWE-264 Low
No
No
9.26a~dfsg-0+deb9u5, 9.27~dfsg-2+deb10u2 29.08.2019 SB2019081208
SB2019083010
SB2019090215
and 10 more
#VU20468 - Permissions, Privileges, and Access Controls
CVE-2019-14811
CWE-264 Low
Public exploit available
No
9.26a~dfsg-0+deb9u5, 9.27~dfsg-2+deb10u2 29.08.2019 SB2019081208
SB2019083010
SB2019090215
and 10 more
#VU20059 - Permissions, Privileges, and Access Controls
CVE-2019-10216
CWE-264 Low
No
No
9.26a~dfsg-0+deb9u4 12.08.2019 SB2019081208
SB2019081209
SB2019081210
and 9 more
#VU18433 - Memory corruption
CVE-2019-3839
CWE-119 High
No
No
9.26a~dfsg-0+deb9u3 13.05.2019 SB2019051301
SB2019050708
SB2019050717
and 6 more
#VU18288 - Exposed Dangerous Method or Function
CVE-2019-3835
CWE-749 Medium
No
No
9.26a~dfsg-0+deb9u2 17.04.2019 SB2019041703
SB2019041105
SB2019040206
and 11 more
#VU18055 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2019-3838
CWE-78 High
No
No
9.26a~dfsg-0+deb9u2 22.03.2019 SB2019032201
SB2019041703
SB2019041105
and 12 more
#VU17230 - Command injection
CVE-2019-6116
CWE-77 Low
No
No
9.26a~dfsg-0+deb9u1 27.01.2019 SB2019012310
SB2019012703
SB2019013004
and 17 more
#VU16576 - Stack-based buffer overflow
CVE-2018-16802
CWE-121 High
No
No
9.20~dfsg-3.2+deb9u5 17.12.2018 SB2018121810
SB2018091604
SB2018091403
and 1 more
#VU14690 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2018-16509
CWE-78 High
Public exploit available
Exploited
9.20~dfsg-3.2+deb9u5 07.09.2018 SB2018090708
SB2018091502
SB2018120409
and 3 more