Apple Cups vulnerabilities

127 known vulnerabilities affecting apple/cups.

Total CVEs
127
CISA KEV
0
Public exploits
13
Exploited in wild
0
Severity breakdown
CRITICAL21HIGH32MEDIUM62LOW12

Vulnerabilities

Page 7 of 7
CVE-2002-1367CRITICALCVSS 10.0≥ 0, < 1.1.18-12002-12-26
CVE-2002-1367 [CRITICAL] CVE-2002-1367: Common Unix Printing System (CUPS) 1 Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to add printers without authentication via a certain UDP packet, which can then be used to perform unauthorized activities such as stealing the local root certificate for the administration server via a "need authorization" page, as demonstrated by new-coke.
osv
CVE-2002-1369CRITICALCVSS 10.0≥ 0, < 1.1.18-12002-12-26
CVE-2002-1369 [CRITICAL] CVE-2002-1369: jobs jobs.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly use the strncat function call when processing the options string, which allows remote attackers to execute arbitrary code via a buffer overflow attack.
osv
CVE-2002-1383CRITICALCVSS 10.0≥ 0, < 1.1.18-12002-12-26
CVE-2002-1383 [CRITICAL] CVE-2002-1383: Multiple integer overflows in Common Unix Printing System (CUPS) 1 Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, as demonstrated by mksun.
osv
CVE-2002-1371HIGHCVSS 7.5≥ 0, < 1.1.18-12002-12-26
CVE-2002-1371 [HIGH] CVE-2002-1371: filters/image-gif filters/image-gif.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check for zero-length GIF images, which allows remote attackers to execute arbitrary code via modified chunk headers, as demonstrated by nogif.
osv
CVE-2002-1368HIGHCVSS 7.5PoC≥ 0, < 1.1.18-12002-12-26
CVE-2002-1368 [HIGH] CVE-2002-1368: Common Unix Printing System (CUPS) 1 Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative arguments to be fed into memcpy() calls via HTTP requests with (1) a negative Content-Length value or (2) a negative length in a chunked transfer encoding.
osv
CVE-2002-1372HIGHCVSS 7.5≥ 1.1.14, ≤ 1.1.172002-12-26
CVE-2002-1372 [HIGH] CWE-252 CVE-2002-1372: Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values o Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values of various file and socket operations, which could allow a remote attacker to cause a denial of service (resource exhaustion) by causing file descriptors to be assigned and not released, as demonstrated by fanta.
nvdosv
CVE-2002-1366MEDIUMCVSS 6.2≥ 0, < 1.1.18-12002-12-26
CVE-2002-1366 [MEDIUM] CVE-2002-1366: Common Unix Printing System (CUPS) 1 Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows local users with lp privileges to create or overwrite arbitrary files via file race conditions, as demonstrated by ice-cream.
osv