HIGH

CVE-2018-19475

CVSS v3

7.8

HIGH

EPSS Score

63.6%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same.

Technical details

Published
11/23/2018

Frequently asked questions

What is CVE-2018-19475?

psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same.

Is CVE-2018-19475 actively exploited?

Active exploitation of CVE-2018-19475 has not been confirmed. The EPSS score is 63.6%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2018-19475?

CVE-2018-19475 has a CVSS v3 base score of 7.8 (HIGH severity).

Is CVE-2018-19475 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.