CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “artifex”

176 vulnerabilities found for “artifex”

Page 1 of 9

CVE-2023-51105
HIGH7.5

A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function bmp_decompress_rle4() of load-bmp.c.

artifex / mupdf
Network
Published Dec 26, 2023
Page 1 of 9
CVE-2023-51104
HIGH7.5

A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function pnm_binary_read_image() of load-pnm.c when span equals zero.

artifex / mupdf
Network
Published Dec 26, 2023
CVE-2023-51103
HIGH7.5

A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in the function fz_new_pixmap_from_float_data() of pixmap.c.

artifex / mupdf
Network
Published Dec 26, 2023
CVE-2023-31794
MEDIUM5.5

MuPDF v1.21.1 was discovered to contain an infinite recursion in the component pdf_mark_list_push. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

artifex / mupdf
Local
Published Oct 31, 2023
CVE-2020-26683
MEDIUM5.5

A memory leak issue discovered in /pdf/pdf-font-add.c in Artifex Software MuPDF 1.17.0 allows attackers to obtain sensitive information.

artifex / mupdf
Local
Published Aug 22, 2023
CVE-2020-21896
MEDIUM5.5

A Use After Free vulnerability in svg_dev_text_span_as_paths_defs function in source/fitz/svg-device.c in Artifex Software MuPDF 1.16.0 allows remote attackers to cause a denial of service via opening of a crafted PDF file.

artifex / mupdf
Local
Published Aug 22, 2023
CVE-2021-4216
MEDIUM5.5

A Floating point exception (division-by-zero) flaw was found in Mupdf for zero width pages in muraster.c. It is fixed in Mupdf-1.20.0-rc1 upstream.

artifex / mupdf
Local
Published Aug 26, 2022
CVE-2020-19609
MEDIUM5.5

Artifex MuPDF before 1.18.0 has a heap based buffer over-write in tiff_expand_colormap() function when parsing TIFF files allowing attackers to cause a denial of service.

artifex / mupdf+1
Local
Published Jul 21, 2021
CVE-2021-37220
MEDIUM5.5

MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.

artifex / mupdf+1
Local
Published Jul 21, 2021
CVE-2021-3407
MEDIUM5.5

A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences.

artifex / mupdf+4
Local
Published Feb 23, 2021
CVE-2020-16600
HIGH7.8

A Use After Free vulnerability exists in Artifex Software, Inc. MuPDF library 1.17.0-rc1 and earlier when a valid page was followed by a page with invalid pixmap dimensions, causing bander - a static - to point to previously freed memory instead of a newband_writer.

artifex / mupdf+1
Local
Published Dec 9, 2020
CVE-2020-26519
MEDIUM5.5

Artifex MuPDF before 1.18.0 has a heap based buffer over-write when parsing JBIG2 files allowing attackers to cause a denial of service.

artifex / mupdf+4
Local
Published Oct 2, 2020
CVE-2018-18284
HIGH8.6

Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator.

artifex / ghostscript+16
Local
Published Oct 19, 2018
CVE-2018-16510
HIGH7.8

An issue was discovered in Artifex Ghostscript before 9.24. Incorrect exec stack handling in the "CS" and "SC" PDF primitives could be used by remote attackers able to supply crafted PDFs to crash the interpreter or possibly have unspecified other impact.

artifex / ghostscript+4
Local
Published Sep 5, 2018
CVE-2018-16513
HIGH7.8

In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the setcolor function to crash the interpreter or possibly have unspecified other impact.

artifex / ghostscript+9
Local
Published Sep 5, 2018
CVE-2018-16509
HIGH7.8

An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction.

debian / debian_linux+13
Local
Published Sep 5, 2018
CVE-2018-15911
HIGH7.8

In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode operator to crash the interpreter or potentially execute code.

debian / debian_linux+15
Local
Published Aug 28, 2018
CVE-2018-15909
HIGH7.8

In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScript files to crash the interpreter or potentially execute code.

debian / debian_linux+14
Local
Published Aug 27, 2018
CVE-2018-15910
HIGH7.8

In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the LockDistillerParams parameter to crash the interpreter or execute code.

debian / debian_linux+13
Local
Published Aug 27, 2018
CVE-2016-9601
MEDIUM5.3

ghostscript before version 9.21 is vulnerable to a heap based buffer overflow that was found in the ghostscript jbig2_decode_gray_scale_image function which is used to decode halftone segments in a JBIG2 image. A document (PostScript or PDF) with an embedded, specially crafted, jbig2 image could trigger a segmentation fault in ghostscript.

artifex / gpl_ghostscript+3
Network
Published Apr 24, 2018