Apple Cups vulnerabilities
127 known vulnerabilities affecting apple/cups.
Total CVEs
127
CISA KEV
0
Public exploits
16
Exploited in wild
1
Severity breakdown
CRITICAL21HIGH32MEDIUM62LOW12
Vulnerabilities
Page 4 of 7
CVE-2025-61915P4MEDIUMCVSS 6.7≥ 0, < 2.4.15-12025-11-29
CVE-2025-61915 [MEDIUM] CVE-2025-61915: OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write. This issue has been patched in
osv
CVE-2011-3170P3MEDIUMCVSS 5.1≤ 1.4.8v1.1+66 more2011-08-19
CVE-2011-3170 [MEDIUM] CVE-2011-3170: The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does not properly handle t
The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does not properly handle the first code word in an LZW stream, which allows remote attackers to trigger a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted stream, a different vulnerability than CVE-2011-2896.
nvdosv
CVE-2014-9679P4MEDIUMCVSS 6.8≤ 2.0.12015-02-19
CVE-2014-9679 [MEDIUM] CWE-119 CVE-2014-9679: Integer underflow in the cupsRasterReadPixels function in filter/raster.c in CUPS before 2.0.2 allow
Integer underflow in the cupsRasterReadPixels function in filter/raster.c in CUPS before 2.0.2 allows remote attackers to have unspecified impact via a malformed compressed raster file, which triggers a buffer overflow.
nvdosv
CVE-2010-0542P4MEDIUMCVSS 6.8≤ 1.4.3v1.1+60 more2010-06-21
CVE-2010-0542 [MEDIUM] CWE-264 CVE-2010-0542: The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.
The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.
nvdosv
CVE-2002-1371P4HIGHCVSS 7.5≥ 0, < 1.1.18-12002-12-26
CVE-2002-1371 [HIGH] CVE-2002-1371: filters/image-gif
filters/image-gif.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check for zero-length GIF images, which allows remote attackers to execute arbitrary code via modified chunk headers, as demonstrated by nogif.
osv
CVE-2005-3628P4HIGHCVSS 7.5≥ 0, < 1.1.22-72005-12-31
CVE-2005-3628 [HIGH] CVE-2005-3628: Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream
Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via unknown attack vectors.
osv
CVE-2009-3553P4HIGHCVSS 7.5v1.3.7v1.3.102009-11-20
CVE-2009-3553 [HIGH] CWE-416 CVE-2009-3553: Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly
nvdosv
CVE-2010-0302P4HIGHCVSS 7.5fixed in 1.4.42010-03-05
CVE-2010-0302 [HIGH] CVE-2010-0302: Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, re
nvdosv
CVE-2008-1374P4MEDIUMCVSS 6.8≤ 1.3.112008-04-04
CVE-2008-1374 [MEDIUM] CVE-2008-1374: Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, when running on 64-b
Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, when running on 64-bit platforms, allows remote attackers to execute arbitrary code via a crafted PDF file. NOTE: this issue is due to an incomplete fix for CVE-2004-0888.
nvd
CVE-2018-4300P4MEDIUMCVSS 5.9fixed in 2.2.10vVersions prior to: v2.2.102019-04-03
CVE-2018-4300 [MEDIUM] CWE-200 CVE-2018-4300: The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthor
The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the web interface is enabled. This issue affected versions prior to v2.2.10.
nvdosv
CVE-2009-0791P4MEDIUMCVSS 6.8v1.1.17v1.1.22+1 more2009-06-09
CVE-2009-0791 [MEDIUM] CWE-189 CVE-2009-0791: Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the pdftops filter in CUP
Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the pdftops filter in CUPS 1.1.17, 1.1.22, and 1.3.7, GPdf, and kdegraphics KPDF, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file that triggers a heap-based buffer overflow, possibly related to (1
nvdosv
CVE-2010-3702P4HIGHCVSS 7.5≤ 1.3.112010-11-05
CVE-2010-3702 [HIGH] CWE-476 CVE-2010-3702: The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference.
nvd
CVE-2005-4873P4HIGHCVSS 7.5≥ 0, < 1.1.23-10sarge12005-12-31
CVE-2005-4873 [HIGH] CVE-2005-4873: Multiple stack-based buffer overflows in the phpcups PHP module for CUPS 1
Multiple stack-based buffer overflows in the phpcups PHP module for CUPS 1.1.23rc1 might allow context-dependent attackers to execute arbitrary code via vectors that result in long function parameters, as demonstrated by the cups_get_dest_options function in phpcups.c.
osv
CVE-2009-0164P4MEDIUMCVSS 6.4≤ 1.3.9v1.1+54 more2009-04-24
CVE-2009-0164 [MEDIUM] CWE-20 CVE-2009-0164: The web interface for CUPS before 1.3.10 does not validate the HTTP Host header in a client request,
The web interface for CUPS before 1.3.10 does not validate the HTTP Host header in a client request, which makes it easier for remote attackers to conduct DNS rebinding attacks.
nvdosv
CVE-2023-4504P4HIGHCVSS 7.0≥ 0, < 2.3.3op2-3+deb11u4≥ 0, < 2.4.2-3+deb12u2+1 more2023-09-21
CVE-2023-4504 [HIGH] CVE-2023-4504: Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffe
Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.
osv
CVE-2025-58364P4MEDIUMCVSS 5.3≥ 0, < 2.3.3op2-3+deb11u10≥ 0, < 2.4.2-3+deb12u9+2 more2025-09-11
CVE-2025-58364 [MEDIUM] CVE-2025-58364: OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, an unsafe deserialization and validation of printer attributes causes null dereference in the libcups library. This is a remote DoS vulnerability available in local subnet in default configurations. It can cause the cups & cups
osv
CVE-2022-26691P4MEDIUMCVSS 6.7fixed in 499.42022-05-26
CVE-2022-26691 [MEDIUM] CWE-697 CVE-2022-26691: A logic issue was addressed with improved state management. This issue is fixed in Security Update 2
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.
nvdosv
CVE-2005-3625P4CRITICALCVSS 10.0≥ 0, < 1.1.22-72005-12-31
CVE-2005-3625 [CRITICAL] CVE-2005-3625: Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
osv
CVE-2017-18248P4MEDIUMCVSS 5.3fixed in 2.2.62018-03-26
CVE-2017-18248 [MEDIUM] CWE-20 CVE-2017-18248: The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be
The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attackers by sending print jobs with an invalid username, related to a D-Bus notification.
nvdosv
CVE-2007-5848P4HIGHCVSS 7.2≥ 0, < 1.2.02007-12-19
CVE-2007-5848 [HIGH] CVE-2007-5848: Buffer overflow in CUPS in Apple Mac OS X 10
Buffer overflow in CUPS in Apple Mac OS X 10.4.11 allows local admin users to execute arbitrary code via a crafted URI to the CUPS service.
osv