CVE-2016-10317: Artifex Ghostscript

High severity, CVSS 7.8. EPSS: 2.3% chance of exploitation in the next 30 days.

The fill_threshhold_buffer function in base/gxht_thresh.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PostScript document.

Affected products

  • Artifex Ghostscript: version 9.20 only

Published 2017-04-03. Last modified 2026-06-17.