CVE-2023-36664High· 7.8▾ MidnightPoC availableArtifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 42.9 · likelihood 0.8 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 27.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
3.2%
3.2% → 4.3%
4 GitHub repos
Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
ghostscript < 10.01.2debian_linux = 11.0debian_linux = 12.0fedora = 37fedora = 38Upgrade past the affected range:
ghostscript 10.01.2Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-39919Critical· 9.8Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 imag…
CVE-2023-38559Medium· 5.5A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript
CVE-2026-92413Medium· 4.3A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9
CVE-2021-1256Medium· 6.0A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite files on the file system of an affected device by using directory traversal techniques
CVE-2025-5273Medium· 6.5Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Files or Directories Accessible to External Parties via the get-markdown-file tool
CVE-2026-77884High· 7.1Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network