Known vulnerabilities in ghostscript (Red Hat package)
Vendor:
Red Hat Inc.
Software:
ghostscript (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:ghostscript_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
44
Public exploits:
3
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
9.54.0-7.el9_0.4
9.54.0-12.el9_2.3
10.02.1-16.el10_0
9.54.0-18.el9_6
9.27-16.el8_10
9.07-20.el7_3.1
8.70-21.el6_8.1
9.54.0-12.el9_2.2
9.27-2.el8_4.1
9.54.0-12.el9_2.1
9.25-6.el8_2.1
9.27-6.el8_8.1
9.27-2.el8_6.1
9.54.0-7.el9_0.3
9.27-13.el8_10
9.54.0-16.el9_4
8.70-14.el5_8.1
8.70-14.el6_3.1
8.70-6.el5_7.6
8.70-11.el6_2.6
8.15.2-9.4.el5_3.7
7.07-33.2.el4_7.8
7.07-33.2.el4_7.5
8.15.2-9.4.el5_3.4
7.07-33.2.el4_6.1
8.15.2-9.1.el5_1.1
9.27-12.el8
9.27-11.el8
9.54.0-13.el9
9.54.0-14.el9_3
9.54.0-11.el9_2
9.54.0-7.el9_0.2
9.54.0-10.el9_2
9.54.0-7.el9_0.1
9.07-29.el7_5.2
9.27-1.el8
9.25-2.el7
9.07-28.el7
7.07-33.13.el4
9.07-28.el7_4
9.07-20.el7_3
8.70-24.el6_10
8.70-23.el6_9
8.70-23.el6
8.70-21.el6_8
8.70-14.el6
8.70-11.el6_2
8.70-11.el6_1
8.70-11.el6
8.70-6.el6
8.70-21.el6
8.70-19.el6
8.70-15.el6_4
8.70-14.el6_3
Vulnerabilities (44)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU106098 - Memory corruption CVE-2025-27832 |
CWE-119 | High | 9.54.0-7.el9_0.4, 9.54.0-12.el9_2.3, 10.02.1-16.el10_0 | 27.03.2025 |
SB2025032721 SB2025032723 SB2025032729 and 17 more |
||
| #VU99618 - Improper input validation CVE-2024-46951 |
CWE-20 | High | 9.27-16.el8_10, 9.54.0-18.el9_6 | 01.11.2024 |
SB2024110189 SB2024110791 SB2024110792 and 16 more |
||
| #VU99619 - Improper input validation CVE-2024-46952 |
CWE-20 | High | 9.27-16.el8_10, 9.54.0-18.el9_6 | 01.11.2024 |
SB2024110189 SB2024110898 SB2024110899 and 12 more |
||
| #VU99620 - Improper input validation CVE-2024-46954 |
CWE-20 | High | 9.27-16.el8_10, 9.54.0-18.el9_6 | 01.11.2024 |
SB2024110189 SB20241112107 SB20241112108 and 7 more |
||
| #VU99617 - Out-of-bounds write CVE-2024-46956 |
CWE-787 | High | 9.27-16.el8_10, 9.54.0-18.el9_6 | 01.11.2024 |
SB2024110189 SB2024110192 SB2024110791 and 13 more |
||
| #VU99616 - Integer overflow CVE-2024-46953 |
CWE-190 | High | 9.27-16.el8_10, 9.54.0-18.el9_6 | 01.11.2024 |
SB2024110189 SB2024110192 SB2024110791 and 12 more |
||
| #VU92284 - Improper input validation CVE-2024-33870 |
CWE-20 | High | 9.54.0-12.el9_2.2 | 19.06.2024 |
SB20240613135 SB2024061967 SB2024062733 and 13 more |
||
| #VU92283 - Improper input validation CVE-2024-33869 |
CWE-20 | High | 9.54.0-12.el9_2.2 | 19.06.2024 |
SB20240613135 SB2024061967 SB20240702141 and 13 more |
||
| #VU92282 - Use of Externally-Controlled Format String CVE-2024-29510 |
CWE-134 | High | 9.54.0-12.el9_2.2 | 19.06.2024 |
SB20240613135 SB2024061967 SB2024062733 and 14 more |
||
| #VU92102 - Uncontrolled Search Path Element CVE-2024-33871 |
CWE-427 | High | 9.25-6.el8_2.1, 9.27-2.el8_4.1, 9.27-2.el8_6.1, 9.27-6.el8_8.1, 9.27-13.el8_10, 9.54.0-7.el9_0.3, 9.54.0-12.el9_2.1, 9.54.0-16.el9_4 | 13.06.2024 |
SB20240613135 SB20240613136 SB2024061422 and 28 more |
||
| #VU83483 - Use of Potentially Dangerous Function CVE-2023-4042 |
CWE-676 | Low | 9.27-11.el8 | 24.11.2023 |
SB2023112469 SB2024041942 SB2024050134 and 1 more |
||
| #VU83447 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2023-46751 |
CWE-611 | High | 9.27-16.el8_10, 9.54.0-18.el9_6 | 23.11.2023 |
SB20231123106 SB2023121241 SB2023121601 and 10 more |
||
| #VU81977 - Use of Potentially Dangerous Function CVE-2023-43115 |
CWE-676 | High | 9.54.0-7.el9_0.2, 9.54.0-11.el9_2, 9.54.0-14.el9_3 | 12.10.2023 |
SB2023101289 SB2023101290 SB2023101291 and 13 more |
||
| #VU80810 - Divide By Zero CVE-2020-21710 |
CWE-369 | Low | 9.27-12.el8 | 14.09.2023 |
SB2023091464 SB2023091465 SB2023100671 and 2 more |
||
| #VU79041 - Memory corruption CVE-2023-38559 |
CWE-119 | Medium | 9.27-11.el8, 9.54.0-13.el9 | 07.08.2023 |
SB2023080739 SB2023080850 SB2023081723 and 18 more |
||
| #VU77939 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2023-36664 |
CWE-78 | High | 9.54.0-7.el9_0.1, 9.54.0-10.el9_2 | 04.07.2023 |
SB2023070430 SB2023070432 SB2023071037 and 18 more |
||
| #VU74502 - Memory corruption CVE-2023-28879 |
CWE-119 | High | 9.27-11.el8, 9.54.0-13.el9 | 06.04.2023 |
SB2023040620 SB2023040626 SB2023040731 and 21 more |
||
| #VU67506 - Heap-based Buffer Overflow CVE-2020-27792 |
CWE-122 | High | 9.27-16.el8_10 | 20.09.2022 |
SB2019081208 SB2022092031 SB2022092732 and 3 more |
||
| #VU45830 - Improper input validation CVE-2020-16288 |
CWE-20 | Medium | 9.27-1.el8 | 13.08.2020 |
SB2020082616 SB2020082617 SB2020083001 and 3 more |
||
| #VU45833 - Improper input validation CVE-2020-16291 |
CWE-20 | Medium | 9.27-1.el8 | 13.08.2020 |
SB2020082616 SB2020082617 SB2020083001 and 3 more |
Showing elements 1 - 20 out of 44