← Vulnerability feed

Vulnerability record · CVE-2020-36773 · published 4 February 2024

CVE-2020-36773: Artifex ghostscript use after free vulnerability

Artifex · Ghostscript

Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).

9.8 CVSS 3.1 Critical EPSS 0.88% · top 42.6% CWE-416 · Use after freeCWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score
0.88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-36773 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2017-8291Ghostscript -dSAFER bypass and command execution via type confusionGhostscript through 2017-04-26 contains a type confusion in .rsdparams handling that lets a crafted .eps document bypass the -dSAFER sandbox. A "/Out…KEVEPSS 97%analysed9.9CVE-2021-3781Ghostscript -dSAFER sandbox escape via crafted pipe commandGhostscript's -dSAFER sandbox can be escaped by injecting a specially crafted pipe command, allowing a malicious document to run arbitrary commands a…EPSS 84%analysed9.8CVE-2025-27836Artifex ghostscript classic buffer overflow vulnerabilityAn issue was discovered in Artifex Ghostscript before 10.05.0. The BJ10V device has a Print buffer overflow in contrib/japanese/gdev10v.c.EPSS 0.59%9.8CVE-2025-27837Artifex ghostscript path traversal vulnerabilityAn issue was discovered in Artifex Ghostscript before 10.05.0. Access to arbitrary files can occur through a truncated path with invalid UTF-8 charac…EPSS 0.61%9.8CVE-2025-27831Artifex ghostscript classic buffer overflow vulnerabilityAn issue was discovered in Artifex Ghostscript before 10.05.0. The DOCXWRITE TXTWRITE device has a text buffer overflow via long characters to device…EPSS 0.59%9.8CVE-2025-27832Artifex ghostscript classic buffer overflow vulnerabilityAn issue was discovered in Artifex Ghostscript before 10.05.0. The NPDL device has a Compression buffer overflow for contrib/japanese/gdevnpdl.c.EPSS 0.82%9.8CVE-2023-28879Artifex ghostscript out-of-bounds write vulnerabilityIn Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in…EPSS 6.3%9.8CVE-2020-15900Artifex ghostscript out-of-bounds write vulnerabilityA memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file acce…EPSS 5.2%

Source: NIST National Vulnerability Database (record CVE-2020-36773), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.