artifex has 3 CVEs on record between 2023 and 2026. 1 was published in the last 90 days. The median CVSS is 5.5 (medium). Most affected products: ghostscript (2), MuPDF (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.5
- Publish → KEV
- —
- Last 90 days
- 1 prev 0
Worst active — by depth score
CVE-2023-36664High· 7.8Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).56CVE-2026-92413Medium· 4.3A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c936CVE-2023-38559Medium· 5.5A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript30
artifex vulnerabilities
CVEs affecting artifex, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-92413Medium· 4.3PoCA flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9
A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability is the function pdf_open_filter of the file pdf-stream.c of the component PDF Xref Loading. Executing a manipulation ca…
CVE-2023-38559Medium· 5.5A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript
A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.
CVE-2023-36664High· 7.8PoCArtifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).