cbcvebase.

Debian Cups vulnerabilities

116 known vulnerabilities affecting debian/cups.

Total CVEs
116
CISA KEV
0
Public exploits
16
Exploited in wild
1
Severity breakdown
CRITICAL13HIGH27MEDIUM49LOW27

Vulnerabilities

Page 5 of 6
CVE-2008-1373P4MEDIUMCVSS 2.6fixed in cups 1.3.7-1 (bookworm)2008
CVE-2008-1373 [LOW] CVE-2008-1373: cups - Buffer overflow in the gif_read_lzw function in CUPS 1.3.6 allows remote attacke... Buffer overflow in the gif_read_lzw function in CUPS 1.3.6 allows remote attackers to have an unknown impact via a GIF file with a large code_size value, a similar issue to CVE-2006-4484. Scope: local bookworm: resolved (fixed in 1.3.7-1) bullseye: resolved (fixed in 1.3.7-1) forky: resolved (fixed in 1.3.7-1) sid: resolved (fixed in 1.3.7-1) trixie: resolved (fixed in 1.
debian
CVE-2018-4181P4MEDIUMCVSS 5.5fixed in cups 2.2.8-2 (bookworm)2018
CVE-2018-4181 [MEDIUM] CVE-2018-4181: cups - In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was ad... In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions. Scope: local bookworm: resolved (fixed in 2.2.8-2) bullseye: resolved (fixed in 2.2.8-2) forky: resolved (fixed in 2.2.8-2) sid: resolved (fixed in 2.2.8-2) trixie: resolved (fixed in 2.2.8-2)
debian
CVE-2019-2228P4MEDIUMCVSS 5.5fixed in cups 2.3.1-1 (bookworm)2019
CVE-2019-2228 [MEDIUM] CVE-2019-2228: cups - In array_find of array.c, there is a possible out-of-bounds read due to an incor... In array_find of array.c, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to local information disclosure in the printer spooler with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-111210196 Scope: loca
debian
CVE-2020-10001P4MEDIUMCVSS 5.5fixed in cups 2.3.3op2-1 (bookworm)2020
CVE-2020-10001 [MEDIUM] CVE-2020-10001: cups - An input validation issue was addressed with improved memory handling. This issu... An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to read restricted memory. Scope: local bookworm: resolved (fixed in 2.3.3op2-1) bullseye: resolved (fixed in 2.3.3op2-1) forky: resolved (fixed in 2.3
debian
CVE-2019-2180P4MEDIUMCVSS 5.5fixed in cups 2.2.12-1 (bookworm)2019
CVE-2019-2180 [MEDIUM] CVE-2019-2180: cups - In ippSetValueTag of ipp.c in Android 8.0, 8.1 and 9, there is a possible out of... In ippSetValueTag of ipp.c in Android 8.0, 8.1 and 9, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure from the printer service with no additional execution privileges needed. User interaction is not needed for exploitation. Scope: local bookworm: resolved (fixed in 2.2.12-1) bullseye: resolved (fi
debian
CVE-2025-58436P4MEDIUMCVSS 5.1fixed in cups 2.4.15-1 (forky)2025
CVE-2025-58436 [MEDIUM] CVE-2025-58436: cups - OpenPrinting CUPS is an open source printing system for Linux and other Unix-lik... OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a client that connects to cupsd but sends slow messages, e.g. only one byte per second, delays cupsd as a whole, such that it becomes unusable by other clients. This issue has been patched in version 2.4.15. Scope: local bookworm: open bullsey
debian
CVE-2007-0720P4LOWCVSS 5.0fixed in cups 1.2.7-1 (bookworm)2007
CVE-2007-0720 [MEDIUM] CVE-2007-0720: cups - The CUPS service on multiple platforms allows remote attackers to cause a denial... The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection, which prevents other requests from being accepted. Scope: local bookworm: resolved (fixed in 1.2.7-1) bullseye: resolved (fixed in 1.2.7-1) forky: resolved (fixed in 1.2.7-1) sid: resolved (fixed in 1.2.7-1) trixie: res
debian
CVE-2007-4045P4MEDIUMCVSS 5.0fixed in cups 1.2 (bookworm)2007
CVE-2007-4045 [MEDIUM] CVE-2007-4045: cups - The CUPS service, as used in SUSE Linux before 20070720 and other Linux distribu... The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspecified vectors related to an incomplete fix for CVE-2007-0720 that introduced a different denial of service problem in SSL negotiation. Scope: local bookworm: resolved (fixed in 1.2) bullseye: resolved (fixed in 1.2) forky
debian
CVE-2009-1196P4MEDIUMCVSS 5.0fixed in cups 1.1.99.b1.r4748-1 (bookworm)2009
CVE-2009-1196 [MEDIUM] CVE-2009-1196: cups - The directory-services functionality in the scheduler in CUPS 1.1.17 and 1.1.22 ... The directory-services functionality in the scheduler in CUPS 1.1.17 and 1.1.22 allows remote attackers to cause a denial of service (cupsd daemon outage or crash) via manipulations of the timing of CUPS browse packets, related to a "pointer use-after-delete flaw." Scope: local bookworm: resolved (fixed in 1.1.99.b1.r4748-1) bullseye: resolved (fixed in 1.1.99.b1.r4748
debian
CVE-2010-2432P4MEDIUMCVSS 5.0fixed in cups 1.4.4-1 (bookworm)2010
CVE-2010-2432 [MEDIUM] CVE-2010-2432: cups - The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, ... The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for authorization, which allows remote CUPS servers to cause a denial of service (infinite loop) via HTTP_UNAUTHORIZED responses. Scope: local bookworm: resolved (fixed in 1.4.4-1) bullseye: resolved (fixed in 1.4.4-1) forky: re
debian
CVE-2002-1384P4HIGHCVSS 7.2fixed in cups 1.1.18-1 (bookworm)2002
CVE-2002-1384 [HIGH] CVE-2002-1384: cups - Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS ... Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code via a ColorSpace entry with a large number of elements, as demonstrated by cups-pdf. Scope: local bookworm: resolved (fixed in 1.1.18-1) bullseye: resolved (fixed in 1.1.18-1) forky: resolved (fixed in 1.1.18-1) sid: resolved (fixed
debian
CVE-2010-0393P4MEDIUMCVSS 6.9fixed in cups 1.4.2-9.1 (bookworm)2010
CVE-2010-0393 [MEDIUM] CVE-2010-0393: cups - The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.... The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine the file that provides localized message strings, which allows local users to gain privileges via a file that contains crafted localization data with format string specifiers. Scope: local bookworm: resolved (fixed in 1.4.2
debian
CVE-2005-2874P4MEDIUMCVSS 5.0fixed in cups 1.1.23-1 (bookworm)2005
CVE-2005-2874 [MEDIUM] CVE-2005-2874: cups - The is_path_absolute function in scheduler/client.c for the daemon in CUPS befor... The is_path_absolute function in scheduler/client.c for the daemon in CUPS before 1.1.23 allows remote attackers to cause a denial of service (CPU consumption by tight loop) via a "..\.." URL in an HTTP request. Scope: local bookworm: resolved (fixed in 1.1.23-1) bullseye: resolved (fixed in 1.1.23-1) forky: resolved (fixed in 1.1.23-1) sid: resolved (fixed in 1.1.23-1
debian
CVE-2004-2154P4LOWCVSS 9.8fixed in cups 1.1.20final+rc1-1 (bookworm)2004
CVE-2004-2154 [CRITICAL] CVE-2004-2154: cups - CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitiv... CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowercase letters that are different from what is specified in the directive. Scope: local bookworm: resolved (fixed in 1.1.20final+rc1-1) bullseye: resolved (fixed in 1.1.20final+rc1-1) forky: re
debian
CVE-2014-2856P4MEDIUMCVSS 4.3fixed in cups 1.7.2-1 (bookworm)2014
CVE-2014-2856 [MEDIUM] CVE-2014-2856: cups - Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Pr... Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function. Scope: local bookworm: resolved (fixed in 1.7.2-1) bullseye: resolved (fixed in 1.7.2-1) forky: resolved (fixed in 1.7.2-1) sid: resol
debian
CVE-2009-0146P4LOWCVSS 4.3fixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-0146 [MEDIUM] CVE-2009-0146: cups - Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS... Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2) JBIG2Stream::readSymbolDictSeg. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixi
debian
CVE-2019-8842P4LOWCVSS 3.3fixed in cups 2.3.1-12 (bookworm)2019
CVE-2019-8842 [LOW] CVE-2019-8842: cups - A buffer overflow was addressed with improved bounds checking. This issue is fix... A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. In certain configurations, a remote attacker may be able to submit arbitrary print jobs. Scope: local bookworm: resolved (fixed in 2.3.1-12) bullseye: resolved (fixed in 2.3.1-12) forky: re
debian
CVE-2003-0788P4MEDIUMCVSS 5.0fixed in cups 1.1.19 (bookworm)2003
CVE-2003-0788 [MEDIUM] CVE-2003-0788: cups - Unknown vulnerability in the Internet Printing Protocol (IPP) implementation in ... Unknown vulnerability in the Internet Printing Protocol (IPP) implementation in CUPS before 1.1.19 allows remote attackers to cause a denial of service (CPU consumption from a "busy loop") via certain inputs to the IPP port (TCP 631). Scope: local bookworm: resolved (fixed in 1.1.19) bullseye: resolved (fixed in 1.1.19) forky: resolved (fixed in 1.1.19) sid: resolved (
debian
CVE-2005-3624P4MEDIUMCVSS 5.0fixed in cups 1.1.22-7 (bookworm)2005
CVE-2005-3624 [MEDIUM] CVE-2005-3624: cups - The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, p... The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows. Scope: local bookworm: resolved (fixed in 1.1.22-7) bullseye: resolved (fixed in 1
debian
CVE-2009-0147P4LOWCVSS 4.3fixed in poppler 0.10.6-1 (bookworm)2009
CVE-2009-0147 [MEDIUM] CVE-2009-0147: cups - Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUP... Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3) JBIG2Stream::readGenericBitmap. Scope: local bookworm: resolved bullseye: re
debian
Debian Cups vulnerabilities | cvebase