peter bassill · operator
$ cve CVE-2018-19409 JSON

CVE-2018-19409

9.8
CRITICAL · CVSS 3.0 · EPSS 7.8% (pctl 95)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device is used.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS7.83% — more likely to be exploited than 95% of all CVEs
On CISA KEVno
Public exploitnone known
Published2018-11-21
Last modified2026-06-17

Affected (8)

VendorProduct
artifexghostscript
canonicalubuntu linux
debiandebian linux
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux workstation

References

→ the Explorer  ·  watch your stack  ·  NVD