Apple Cups vulnerabilities
127 known vulnerabilities affecting apple/cups.
Total CVEs
127
CISA KEV
0
Public exploits
16
Exploited in wild
1
Severity breakdown
CRITICAL21HIGH32MEDIUM62LOW12
Vulnerabilities
Page 2 of 7
CVE-2010-2941P3CRITICALCVSS 9.8≤ 1.4.42010-11-05
CVE-2010-2941 [CRITICAL] CWE-416 CVE-2010-2941: ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with
ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.
nvdosv
CVE-2008-5377P4MEDIUMCVSS 6.9PoCv1.3.82008-12-08
CVE-2008-5377 [MEDIUM] CVE-2008-5377: pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /t
pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulnerability than CVE-2001-1333.
nvdosv
CVE-2009-2820P4MEDIUMCVSS 4.3PoC≥ 0, < 1.4.2-12009-11-10
CVE-2009-2820 [MEDIUM] CVE-2009-2820: The web interface in CUPS before 1
The web interface in CUPS before 1.4.2, as used on Apple Mac OS X before 10.6.2 and other platforms, does not properly handle (1) HTTP headers and (2) HTML templates, which allows remote attackers to conduct cross-site scripting (XSS) attacks and HTTP response splitting attacks via vectors related to (a) the product's web interface, (b) the configuration of the print system, and (c) the titles of printed jobs, as demonstrat
osv
CVE-2009-1182P3HIGHCVSS 7.5≤ 1.3.9v1.1+54 more2009-04-23
CVE-2009-1182 [HIGH] CWE-119 CVE-2009-1182: Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earli
Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.
nvd
CVE-2008-0882P3CRITICALCVSS 10.0≥ 0, < 1.3.6-12008-02-21
CVE-2008-0882 [CRITICAL] CVE-2008-0882: Double free vulnerability in the process_browse_data function in CUPS 1
Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via crafted UDP Browse packets to the cupsd port (631/udp), related to an unspecified manipulation of a remote printer. NOTE: some of these details are obtained from third party information.
osv
CVE-2008-0047P3CRITICALCVSS 9.3≥ 0, < 1.3.6-32008-03-18
CVE-2008-0047 [CRITICAL] CVE-2008-0047: Heap-based buffer overflow in the cgiCompileSearch function in CUPS 1
Heap-based buffer overflow in the cgiCompileSearch function in CUPS 1.3.5, and other versions including the version bundled with Apple Mac OS X 10.5.2, when printer sharing is enabled, allows remote attackers to execute arbitrary code via crafted search expressions.
osv
CVE-2004-1269P4MEDIUMCVSS 5.0PoC≥ 0, < 1.1.22-22005-01-10
CVE-2004-1269 [MEDIUM] CVE-2004-1269: lppasswd in CUPS 1
lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subsequent invocations of lppasswd to fail.
osv
CVE-2007-4351P3CRITICALCVSS 10.0≥ 0, < 1.3.4-12007-10-31
CVE-2007-4351 [CRITICAL] CVE-2007-4351: Off-by-one error in the ippReadIO function in cups/ipp
Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted (1) textWithLanguage or (2) nameWithLanguage Internet Printing Protocol (IPP) tag, leading to a stack-based buffer overflow.
osv
CVE-2007-5392P3CRITICALCVSS 9.3≥ 0, < 1.1.22-72007-11-08
CVE-2007-5392 [CRITICAL] CVE-2007-5392: Integer overflow in the DCTStream::reset method in xpdf/Stream
Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF file, resulting in a heap-based buffer overflow.
osv
CVE-2008-3639P3HIGHCVSS 7.5≤ 1.3.8v1.1+53 more2008-10-14
CVE-2008-3639 [HIGH] CWE-119 CVE-2008-3639: Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS before 1.3.9 allows remot
Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via an SGI image with malformed Run Length Encoded (RLE) data containing a small image and a large row count.
nvdosv
CVE-2018-6553P3HIGHCVSS 8.8≥ 0, < 2.2.8-52018-08-10
CVE-2018-6553 [HIGH] CVE-2018-6553: The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links
The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possibly use this issue to escape confinement. This flaw affects versions prior to 2.2.7-1ubuntu2.1 in Ubuntu 18.04 LTS, prior to 2.2.4-7ubuntu3.1 in Ubuntu 17.10, prior to 2.1.3-4ubuntu0.5 in Ubuntu 16.04 LTS, and prior to 1.7.2-0ubuntu1.10 in Ubuntu 14.04 LT
osv
CVE-2003-0195P4MEDIUMCVSS 5.0PoC≥ 0, < 1.1.19final-12003-06-16
CVE-2003-0195 [MEDIUM] CVE-2003-0195: CUPS before 1
CUPS before 1.1.19 allows remote attackers to cause a denial of service via a partial printing request to the IPP port (631), which does not time out.
osv
CVE-2015-3279P3HIGHCVSS 7.5≥ 0, < 1.5.0-162015-07-14
CVE-2015-3279 [HIGH] CVE-2015-3279: Integer overflow in filter/texttopdf
Integer overflow in filter/texttopdf.c in texttopdf in cups-filters before 1.0.71 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted line size in a print job, which triggers a heap-based buffer overflow.
osv
CVE-2007-5393P3CRITICALCVSS 9.3≥ 0, < 1.1.22-72007-11-08
CVE-2007-5393 [CRITICAL] CVE-2007-5393: Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream
Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a PDF file that contains a crafted CCITTFaxDecode filter.
osv
CVE-2008-5286P3HIGHCVSS 7.5v1.1.17v1.1.18+30 more2008-12-01
CVE-2008-5286 [HIGH] CWE-189 CVE-2008-5286: Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 allows remote attack
Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large height value, which bypasses a validation check and triggers a buffer overflow.
nvdosv
CVE-2007-4352P3HIGHCVSS 7.6≥ 0, < 1.1.22-72007-11-08
CVE-2007-4352 [HIGH] CVE-2007-4352: Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream
Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, and other products, allows remote attackers to trigger memory corruption and execute arbitrary code via a crafted PDF file.
osv
CVE-2009-1180P3MEDIUMCVSS 6.8≤ 1.3.9v1.1+54 more2009-04-23
CVE-2009-1180 [MEDIUM] CWE-399 CVE-2009-1180: The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and ot
The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data.
nvd
CVE-2002-1369P3CRITICALCVSS 10.0≥ 0, < 1.1.18-12002-12-26
CVE-2002-1369 [CRITICAL] CVE-2002-1369: jobs
jobs.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly use the strncat function call when processing the options string, which allows remote attackers to execute arbitrary code via a buffer overflow attack.
osv
CVE-2007-3387P3MEDIUMCVSS 6.8≤ 1.3.112007-07-30
CVE-2007-3387 [MEDIUM] CWE-190 CVE-2007-3387: Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppl
Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based buffer overflow in the StreamPredict
nvd
CVE-2024-35235P3MEDIUMCVSS 6.7≥ 0, < 2.3.3op2-3+deb11u7≥ 0, < 2.4.2-3+deb12u6+1 more2024-06-11
CVE-2024-35235 [MEDIUM] CVE-2024-35235: OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 and earlier, when starting the cupsd server with a Listen configuration item pointing to a symbolic link, the cupsd process can be caused to perform an arbitrary chmod of the provided argument, providing world-writable access to the target.
osv