cbcvebase.

Debian Cups vulnerabilities

116 known vulnerabilities affecting debian/cups.

Total CVEs
116
CISA KEV
0
Public exploits
16
Exploited in wild
1
Severity breakdown
CRITICAL13HIGH27MEDIUM49LOW27

Vulnerabilities

Page 1 of 6
CVE-2002-1368P2HIGHCVSS 7.5ExploitedPoCfixed in cups 1.1.18-1 (bookworm)2002
CVE-2002-1368 [HIGH] CVE-2002-1368: cups - Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers... Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative arguments to be fed into memcpy() calls via HTTP requests with (1) a negative Content-Length value or (2) a negative length in a chunked transfer encoding. Scope: local bookworm: resolved (fixed in 1
debian
CVE-2024-47175P1HIGHCVSS 8.6PoCfixed in cups 2.4.2-3+deb12u8 (bookworm)2024
CVE-2024-47175 [HIGH] CVE-2024-47175: cups - CUPS is a standards-based, open-source printing system, and `libppd` can be used... CUPS is a standards-based, open-source printing system, and `libppd` can be used for legacy PPD file support. The `libppd` function `ppdCreatePPDFromIPP2` does not sanitize IPP attributes when creating the PPD buffer. When used in combination with other functions such as `cfGetPrinterAttributes5`, can result in user controlled input and ultimately code execution via Fo
debian
CVE-2015-1158P2CRITICALCVSS 10.0PoCfixed in cups 1.7.5-12 (bookworm)2015
CVE-2015-1158 [CRITICAL] CVE-2015-1158: cups - The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs i... The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-host-name attributes, which allows remote attackers to trigger data corruption for reference-counted strings via a crafted (1) IPP_CREATE_JOB or (2) IPP_PRINT_JOB request, as demonstrated by replacing the configuration file and c
debian
CVE-2008-3641P2MEDIUMCVSS 10.0PoCfixed in cups 1.3.8-1lenny2 (bookworm)2008
CVE-2008-3641 [CRITICAL] CVE-2008-3641: cups - The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows ... The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and pen color opcodes that overwrite arbitrary memory. Scope: local bookworm: resolved (fixed in 1.3.8-1lenny2) bullseye: resolved (fixed in 1.3.8-1lenny2) forky: resolved (fixed in 1.3.8-1lenny2) sid: resolved (fixed in 1.3
debian
CVE-2007-5849P2MEDIUMCVSS 9.3PoCfixed in cups 1.3.5-1 (bookworm)2007
CVE-2007-5849 [CRITICAL] CVE-2007-5849: cups - Integer underflow in the asn1_get_string function in the SNMP back end (backend/... Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute arbitrary code via a crafted SNMP response that triggers a stack-based buffer overflow. Scope: local bookworm: resolved (fixed in 1.3.5-1) bullseye: resolved (fixed in 1.3.5-1) forky: resolved (fixed in 1.3.5-1) sid: re
debian
CVE-2009-0949P3HIGHCVSS 7.5PoCfixed in cups 1.3.10-1 (bookworm)2009
CVE-2009-0949 [HIGH] CVE-2009-0949: cups - The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not pro... The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags. Scope: local bookworm: resolved (fixed in 1.3.10-1) bullseye: resolved
debian
CVE-2008-5183P3LOWCVSS 7.5PoCfixed in cups 1.3.9-13 (bookworm)2008
CVE-2008-5183 [HIGH] CVE-2008-5183: cups - cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attacker... cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference. NOTE: this issue can be triggered remotely by leveraging CVE-2008-5184. Scope: local bookworm: resolved (fixed in 1.3.9-13) bullseye: resolved (fixed in 1.3
debian
CVE-2012-5519P3HIGHCVSS 7.2PoCfixed in cups 1.5.3-2.7 (bookworm)2012
CVE-2012-5519 [HIGH] CVE-2012-5519: cups - CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux... CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface. Scope: local bookworm: resolved (fixed in 1.5.3-2.7) bullseye: resolved (fix
debian
CVE-2004-0558P4MEDIUMCVSS 5.0PoCfixed in cups 1.1.20final+rc1-6 (bookworm)2004
CVE-2004-0558 [MEDIUM] CVE-2004-0558: cups - The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows... The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of service (service hang) via a certain UDP packet to the IPP port. Scope: local bookworm: resolved (fixed in 1.1.20final+rc1-6) bullseye: resolved (fixed in 1.1.20final+rc1-6) forky: resolved (fixed in 1.1.20final+rc1-6) sid: resolved (fixed in 1.1.20fin
debian
CVE-2004-1267P4MEDIUMCVSS 6.5PoCfixed in cups 1.1.22-2 (bookworm)2004
CVE-2004-1267 [MEDIUM] CVE-2004-1267: cups - Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops pro... Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops program for CUPS 1.1.22 allows remote attackers to execute arbitrary code via a crafted HPGL file. Scope: local bookworm: resolved (fixed in 1.1.22-2) bullseye: resolved (fixed in 1.1.22-2) forky: resolved (fixed in 1.1.22-2) sid: resolved (fixed in 1.1.22-2) trixie: resolved (fixed in 1.1.22-
debian
CVE-2019-8696P3HIGHCVSS 8.8fixed in cups 2.2.12-1 (bookworm)2019
CVE-2019-8696 [HIGH] CVE-2019-8696: cups - A buffer overflow issue was addressed with improved memory handling. This issue ... A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra. An attacker in a privileged network position may be able to execute arbitrary code. Scope: local bookworm: resolved (fixed in 2.2.12-1) bullseye: resolved (fixed in 2.2.12-1) forky: resolv
debian
CVE-2019-8675P3HIGHCVSS 8.8fixed in cups 2.2.12-1 (bookworm)2019
CVE-2019-8675 [HIGH] CVE-2019-8675: cups - A buffer overflow issue was addressed with improved memory handling. This issue ... A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra. An attacker in a privileged network position may be able to execute arbitrary code. Scope: local bookworm: resolved (fixed in 2.2.12-1) bullseye: resolved (fixed in 2.2.12-1) forky: resolv
debian
CVE-2017-18190P3HIGHCVSS 7.5fixed in cups 2.2.3-2 (bookworm)2017
CVE-2017-18190 [HIGH] CVE-2017-18190: cups - A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in... A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon in conjunction with DNS rebinding. The localhost.localdomain name is often resolved via a DNS server (neither the OS nor the web browser is responsible for ensuring that
debian
CVE-2008-0053P3CRITICALCVSS 10.0fixed in cups 1.3.6-1 (bookworm)2008
CVE-2008-0053 [CRITICAL] CVE-2008-0053: cups - Multiple buffer overflows in the HP-GL/2-to-PostScript filter in CUPS before 1.3... Multiple buffer overflows in the HP-GL/2-to-PostScript filter in CUPS before 1.3.6 might allow remote attackers to execute arbitrary code via a crafted HP-GL/2 file. Scope: local bookworm: resolved (fixed in 1.3.6-1) bullseye: resolved (fixed in 1.3.6-1) forky: resolved (fixed in 1.3.6-1) sid: resolved (fixed in 1.3.6-1) trixie: resolved (fixed in 1.3.6-1)
debian
CVE-2025-58060P3HIGHCVSS 8.0fixed in cups 2.4.2-3+deb12u9 (bookworm)2025
CVE-2025-58060 [HIGH] CVE-2025-58060: cups - OpenPrinting CUPS is an open source printing system for Linux and other Unix-lik... OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, when the `AuthType` is set to anything but `Basic`, if the request contains an `Authorization: Basic ...` header, the password is not checked. This results in authentication bypass. Any configuration that allows an `AuthType` that is not
debian
CVE-2010-1748P4MEDIUMCVSS 4.3PoCfixed in cups 1.4.4-1 (bookworm)2010
CVE-2010-1748 [MEDIUM] CVE-2010-1748: cups - The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS... The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information fro
debian
CVE-2015-1159P4MEDIUMCVSS 4.3PoCfixed in cups 1.7.5-12 (bookworm)2015
CVE-2015-1159 [MEDIUM] CVE-2015-1159: cups - Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/tem... Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter to help/. Scope: local bookworm: resolved (fixed in 1.7.5-12) bullseye: resolved (fixed in 1.7.5-12) forky: resolved (fixed in 1.7.5-12) sid: resolved (
debian
CVE-2008-5184P3CRITICALCVSS 10.0fixed in cups 1.3.8-1 (bookworm)2008
CVE-2008-5184 [CRITICAL] CVE-2008-5184: cups - The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username... The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy and conduct CSRF attacks via the (1) add and (2) cancel RSS subscription functions. Scope: local bookworm: resolved (fixed in 1.3.8-1) bullseye: resolved (fixed in 1.3.8-1
debian
CVE-2015-3258P3HIGHCVSS 7.5fixed in cups 1.5.0-16 (bookworm)2015
CVE-2015-3258 [HIGH] CVE-2015-3258: cups - Heap-based buffer overflow in the WriteProlog function in filter/texttopdf.c in ... Heap-based buffer overflow in the WriteProlog function in filter/texttopdf.c in texttopdf in cups-filters before 1.0.70 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a small line size in a print job. Scope: local bookworm: resolved (fixed in 1.5.0-16) bullseye: resolved (fixed in 1.5.0-16) forky: resolved (fixed in 1.
debian
CVE-2015-2305P3LOWCVSS 6.8fixed in clamav 0.98.7+dfsg-1 (bookworm)2015
CVE-2015-2305 [MEDIUM] CVE-2015-2305: alpine - Integer overflow in the regcomp implementation in the Henry Spencer BSD regex li... Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in NetBSD through 6.1.5 and other products, might allow context-dependent attackers to execute arbitrary code via a large regular expression that leads to a heap-based buffer overflow. Scope: local bookworm: resolved bullseye:
debian
Debian Cups vulnerabilities | cvebase