cbcvebase.

Apple Cups vulnerabilities

127 known vulnerabilities affecting apple/cups.

Total CVEs
127
CISA KEV
0
Public exploits
16
Exploited in wild
1
Severity breakdown
CRITICAL21HIGH32MEDIUM62LOW12

Vulnerabilities

Page 1 of 7
CVE-2002-1368P2HIGHCVSS 7.5ExploitedPoC≥ 0, < 1.1.18-12002-12-26
CVE-2002-1368 [HIGH] CVE-2002-1368: Common Unix Printing System (CUPS) 1 Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative arguments to be fed into memcpy() calls via HTTP requests with (1) a negative Content-Length value or (2) a negative length in a chunked transfer encoding.
osv
CVE-2024-47175P1CRITICALCVSS 9.8PoC≥ 0, < 2.3.3op2-3+deb11u9≥ 0, < 2.4.2-3+deb12u8+1 more2024-09-26
CVE-2024-47175 [CRITICAL] CVE-2024-47175: CUPS is a standards-based, open-source printing system, and `libppd` can be used for legacy PPD file support CUPS is a standards-based, open-source printing system, and `libppd` can be used for legacy PPD file support. The `libppd` function `ppdCreatePPDFromIPP2` does not sanitize IPP attributes when creating the PPD buffer. When used in combination with other functions such as `cfGetPrinterAttributes5`, can result in user controlled input and ultimately
osv
CVE-2015-1158P2CRITICALCVSS 10.0PoC≥ 0, < 1.7.2-0ubuntu1.62015-06-10
CVE-2015-1158 [CRITICAL] cups vulnerabilities cups vulnerabilities It was discovered that CUPS incorrectly handled reference counting when handling localized strings. A remote attacker could use this issue to escalate permissions, upload a replacement CUPS configuration file, and execute arbitrary code. (CVE-2015-1158) It was discovered that the CUPS templating engine contained a cross-site scripting issue. A remote attacker could use this issue to bypass default configuration settings. (CVE-2
osv
CVE-2008-3641P2CRITICALCVSS 10.0PoC≤ 1.3.8v1.1+53 more2008-10-10
CVE-2008-3641 [CRITICAL] CWE-399 CVE-2008-3641: The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and pen color opcodes that overwrite arbitrary memory.
nvdosv
CVE-2007-5849P2CRITICALCVSS 9.3PoC≥ 0, < 1.3.5-12007-12-19
CVE-2007-5849 [CRITICAL] CVE-2007-5849: Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute arbitrary code via a crafted SNMP response that triggers a stack-based buffer overflow.
osv
CVE-2009-0949P3HIGHCVSS 7.5PoCfixed in 1.3.102009-06-09
CVE-2009-0949 [HIGH] CWE-908 CVE-2009-0949: The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize mem The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags.
nvdosv
CVE-2008-5183P3HIGHCVSS 7.5PoC≤ 1.3.92008-11-21
CVE-2008-5183 [HIGH] CWE-476 CVE-2008-5183: cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference. NOTE: this issue can be triggered remotely by leveraging CVE-2008-5184.
nvdosv
CVE-2012-5519P3HIGHCVSS 7.2PoCv1.4.42012-11-20
CVE-2012-5519 [HIGH] CWE-264 CVE-2012-5519: CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web int CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.
nvdosv
CVE-2004-0558P4MEDIUMCVSS 5.0PoC≥ 0, < 1.1.20final+rc1-62004-09-28
CVE-2004-0558 [MEDIUM] CVE-2004-0558: The Internet Printing Protocol (IPP) implementation in CUPS before 1 The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of service (service hang) via a certain UDP packet to the IPP port.
osv
CVE-2004-1267P4MEDIUMCVSS 6.5PoC≥ 0, < 1.1.22-22005-01-10
CVE-2004-1267 [MEDIUM] CVE-2004-1267: Buffer overflow in the ParseCommand function in hpgl-input Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops program for CUPS 1.1.22 allows remote attackers to execute arbitrary code via a crafted HPGL file.
osv
CVE-2019-8696P3HIGHCVSS 8.8≥ 0, < 2.2.12-12020-10-27
CVE-2019-8696 [HIGH] CVE-2019-8696: A buffer overflow issue was addressed with improved memory handling A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra. An attacker in a privileged network position may be able to execute arbitrary code.
osv
CVE-2019-8675P3HIGHCVSS 8.8≥ 0, < 2.2.12-12020-10-27
CVE-2019-8675 [HIGH] CVE-2019-8675: A buffer overflow issue was addressed with improved memory handling A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra. An attacker in a privileged network position may be able to execute arbitrary code.
osv
CVE-2017-18190P3HIGHCVSS 7.5fixed in 2.2.22018-02-16
CVE-2017-18190 [HIGH] CWE-290 CVE-2017-18190: A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 a A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon in conjunction with DNS rebinding. The localhost.localdomain name is often resolved via a DNS server (neither the OS nor the web browser is responsible
nvdosv
CVE-2012-6094P3CRITICALCVSS 9.8fixed in 1.5.4-1.12019-12-20
CVE-2012-6094 [CRITICAL] CWE-863 CVE-2012-6094: cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could p cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system
nvd
CVE-2008-0053P3CRITICALCVSS 10.0≤ 1.3.5v1.1+52 more2008-03-18
CVE-2008-0053 [CRITICAL] CWE-119 CVE-2008-0053: Multiple buffer overflows in the HP-GL/2-to-PostScript filter in CUPS before 1.3.6 might allow remot Multiple buffer overflows in the HP-GL/2-to-PostScript filter in CUPS before 1.3.6 might allow remote attackers to execute arbitrary code via a crafted HP-GL/2 file.
nvdosv
CVE-2025-58060P3HIGHCVSS 8.0≥ 0, < 2.3.3op2-3+deb11u10≥ 0, < 2.4.2-3+deb12u9+2 more2025-09-11
CVE-2025-58060 [HIGH] CVE-2025-58060: OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, when the `AuthType` is set to anything but `Basic`, if the request contains an `Authorization: Basic ...` header, the password is not checked. This results in authentication bypass. Any configuration that allows an `AuthType` tha
osv
CVE-2010-1748P4MEDIUMCVSS 4.3PoC≤ 1.4.3v1.1+60 more2010-06-17
CVE-2010-1748 [MEDIUM] CWE-119 CVE-2010-1748: The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as us The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensiti
nvdosv
CVE-2015-1159P4MEDIUMCVSS 4.3PoC≥ 0, < 1.7.5-122015-06-26
CVE-2015-1159 [MEDIUM] CVE-2015-1159: Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter to help/.
osv
CVE-2008-5184P3CRITICALCVSS 10.0≤ 1.3.7v1.1+52 more2008-11-21
CVE-2008-5184 [CRITICAL] CWE-255 CVE-2008-5184: The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy and conduct CSRF attacks via the (1) add and (2) cancel RSS subscription functions.
nvdosv
CVE-2015-3258P3HIGHCVSS 7.5≥ 0, < 1.5.0-162015-07-14
CVE-2015-3258 [HIGH] CVE-2015-3258: Heap-based buffer overflow in the WriteProlog function in filter/texttopdf Heap-based buffer overflow in the WriteProlog function in filter/texttopdf.c in texttopdf in cups-filters before 1.0.70 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a small line size in a print job.
osv
Apple Cups vulnerabilities | cvebase