CVE detail
CVE-2020-16303 — CVE-2020-16303
Published 2020-08-13 · Modified 2026-06-17 · Vendor artifex · Product ghostscript · Source nvd
HIGH
severity
CVSS-derived band
0.0179
EPSS probability
exploitation probability, 30d
76.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A use-after-free vulnerability in xps_finish_image_path() in devices/vector/gdevxps.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References