cbcvebase.
CVE-2002-1384
published 2003-01-02

CVE-2002-1384: Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code via a ColorSpace…

PriorityP420high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.69%
49.2th percentile
Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code via a ColorSpace entry with a large number of elements, as demonstrated by cups-pdf.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
applecups>= 0 < 1.1.18-11.1.18-1
applecups>= 0 < 1.1.18-11.1.18-1
applecups>= 0 < 1.1.18-11.1.18-1
applecups>= 0 < 1.1.18-11.1.18-1
debiancups< cups 1.1.18-1 (bookworm)cups 1.1.18-1 (bookworm)
debianxpdf< cups 1.1.18-1 (bookworm)cups 1.1.18-1 (bookworm)
easy_software_productscups
easy_software_productscups
easy_software_productscups
easy_software_productscups
easy_software_productscups
easy_software_productscups
easy_software_productscups
easy_software_productscups
easy_software_productscups
easy_software_productscups
easy_software_productscups
easy_software_productscups
easy_software_productscups
xpdfxpdf
xpdfxpdf
xpdfxpdf
xpdfxpdf
xpdfxpdf
xpdfxpdf

CVSS provenance

nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.