Apple Cups vulnerabilities
127 known vulnerabilities affecting apple/cups.
Total CVEs
127
CISA KEV
0
Public exploits
16
Exploited in wild
1
Severity breakdown
CRITICAL21HIGH32MEDIUM62LOW12
Vulnerabilities
Page 3 of 7
CVE-2020-3898P3HIGHCVSS 7.8≥ 0, < 2.3.1-122020-10-22
CVE-2020-3898 [HIGH] CVE-2020-3898: A memory corruption issue was addressed with improved validation
A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. An application may be able to gain elevated privileges.
osv
CVE-2002-1383P3CRITICALCVSS 10.0≥ 0, < 1.1.18-12002-12-26
CVE-2002-1383 [CRITICAL] CVE-2002-1383: Multiple integer overflows in Common Unix Printing System (CUPS) 1
Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, as demonstrated by mksun.
osv
CVE-2011-2896P3MEDIUMCVSS 5.1≤ 1.4.62011-08-19
CVE-2011-2896 [MEDIUM] CWE-787 CVE-2011-2896: The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PB
The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte function in plug-ins/common/file-gif-load.c in GIMP 2.6.11 and earlier, the LZWReadByte function in img/gifread.c in XPCE in SWI-Prolog 5.10.4 and ea
nvdosv
CVE-2005-3192P3HIGHCVSS 7.5≥ 0, < 1.1.23-132005-12-08
CVE-2005-3192 [HIGH] CVE-2005-3192: Heap-based buffer overflow in the StreamPredictor function in Xpdf 3
Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows remote attackers to execute arbitrary code via a PDF file with an out-of-range numComps (number of components) field.
osv
CVE-2002-1367P3CRITICALCVSS 10.0≥ 0, < 1.1.18-12002-12-26
CVE-2002-1367 [CRITICAL] CVE-2002-1367: Common Unix Printing System (CUPS) 1
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to add printers without authentication via a certain UDP packet, which can then be used to perform unauthorized activities such as stealing the local root certificate for the administration server via a "need authorization" page, as demonstrated by new-coke.
osv
CVE-2009-1179P3MEDIUMCVSS 6.8≤ 1.3.9v1.1+54 more2009-04-23
CVE-2009-1179 [MEDIUM] CWE-189 CVE-2009-1179: Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler b
Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file.
nvd
CVE-2009-0800P3MEDIUMCVSS 6.8≤ 1.3.9v1.1+54 more2009-04-23
CVE-2009-0800 [MEDIUM] CWE-20 CVE-2009-0800: Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and e
Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.
nvd
CVE-2004-0888P4CRITICALCVSS 10.0≥ 0, < 1.1.22-62005-01-27
CVE-2004-0888 [CRITICAL] CVE-2004-0888: Multiple integer overflows in xpdf 2
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
osv
CVE-2008-3640P3MEDIUMCVSS 6.8≤ 1.3.8v1.1+53 more2008-10-14
CVE-2008-3640 [MEDIUM] CWE-189 CVE-2008-3640: Integer overflow in the WriteProlog function in texttops in CUPS before 1.3.9 allows remote attacker
Integer overflow in the WriteProlog function in texttops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow.
nvdosv
CVE-2009-0163P3MEDIUMCVSS 6.8≤ 1.3.9v1.1+54 more2009-04-23
CVE-2009-0163 [MEDIUM] CWE-189 CVE-2009-0163: Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier allows remote attacke
Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a crafted TIFF image, which is not properly handled by the (1) _cupsImageReadTIFF function in the imagetops filter and (2) imagetoraster filter, leading to a heap-bas
nvdosv
CVE-2018-4180P3HIGHCVSS 7.8≥ 0, < 2.2.8-22019-01-11
CVE-2018-4180 [HIGH] CVE-2018-4180: In macOS High Sierra before 10
In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.
osv
CVE-2009-0195P3MEDIUMCVSS 6.8v1.3.92009-04-23
CVE-2009-0195 [MEDIUM] CWE-119 CVE-2009-0195: Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, all
Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrary code via a PDF file with crafted JBIG2 symbol dictionary segments.
nvd
CVE-2017-15400P3HIGHCVSS 7.8≥ 0, < 2.2.3-22018-02-07
CVE-2017-15400 [HIGH] CVE-2017-15400: Insufficient restriction of IPP filters in CUPS in Google Chrome OS prior to 62
Insufficient restriction of IPP filters in CUPS in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker to execute a command with the same privileges as the cups daemon via a crafted PPD file, aka a printer zeroconfig CRLF issue.
osv
CVE-2013-6475P3MEDIUMCVSS 6.8≥ 0, < 1.5.0-162014-03-14
CVE-2013-6475 [MEDIUM] CVE-2013-6475: Multiple integer overflows in (1) OPVPOutputDev
Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, which triggers a heap-based buffer overflow.
osv
CVE-2013-6474P3MEDIUMCVSS 6.8≥ 0, < 1.5.0-162014-03-14
CVE-2013-6474 [MEDIUM] CVE-2013-6474: Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters before 1
Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows remote attackers to execute arbitrary code via a crafted PDF file.
osv
CVE-2005-0064P3HIGHCVSS 7.5≥ 0, < 1.1.22-62005-05-02
CVE-2005-0064 [HIGH] CVE-2005-0064: Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt
Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary code via a PDF file with a large /Encrypt /Length keyLength value.
osv
CVE-2009-0577P4MEDIUMCVSS 6.8v1.1.172009-02-20
CVE-2009-0577 [MEDIUM] CVE-2009-0577: Integer overflow in the WriteProlog function in texttops in CUPS 1.1.17 on Red Hat Enterprise Linux
Integer overflow in the WriteProlog function in texttops in CUPS 1.1.17 on Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2008-3640.
nvd
CVE-2023-34241P4HIGHCVSS 7.1≥ 0, < 2.3.3op2-3+deb11u3≥ 0, < 2.4.2-3+deb12u1+1 more2023-06-22
CVE-2023-34241 [HIGH] CVE-2023-34241: OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like operating systems
OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like operating systems. Starting in version 2.0.0 and prior to version 2.4.6, CUPS logs data of free memory to the logging service AFTER the connection has been closed, when it should have logged the data right before. This is a use-after-free bug that
osv
CVE-2005-3627P4HIGHCVSS 7.5≥ 0, < 1.1.22-72005-12-31
CVE-2005-3627 [HIGH] CVE-2005-3627: Stream
Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via a DCTDecode stream with (1) a large "number of components" value that is not checked by DCTStream::readBaselineSOF or DCTStream::readProgressiveSOF, (2) a large "Huffman table index" value that is not checked by DCTStream::readHuffmanTables, and (3) certain uses of
osv
CVE-2004-1125P4CRITICALCVSS 9.3≥ 0, < 1.1.22-22005-01-10
CVE-2004-1125 [CRITICAL] CVE-2004-1125: Buffer overflow in the Gfx::doImage function in Gfx
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PDF file that causes the boundaries of a maskColors array to be exceeded.
osv