CVE-2021-45949Medium· 5.5▾ SunlitGhostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.4%
3.9 → 5.5
low → medium
Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).
ghostscript >= 9.50, <= 9.54.0debian_linux = 9.0debian_linux = 10.0debian_linux = 11.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-101258High· 7.8A flaw was found in Ghostscript
CVE-2026-39919Critical· 9.8Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 imag…
CVE-2026-103226Medium· 6.3A vulnerability was identified in Artifex Ghostscript up to 10.09.0
CVE-2026-19547High· 7.0Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource file hijacking
CVE-2025-15059High· 7.8GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2026-106564Medium· 5.3ImageMagick is free and open-source software used for editing and manipulating digital images