Easy Software Products Cups vulnerabilities

35 known vulnerabilities affecting easy_software_products/cups.

Total CVEs
35
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH6MEDIUM15LOW4

Vulnerabilities

Page 2 of 2
CVE-2004-1270LOWCVSS 2.1v1.0.4v1.0.4_8+20 more2005-01-10
CVE-2004-1270 [LOW] CVE-2004-1270: lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lppasswd is called, does not verify that the passwd.new file is different from STDERR, which allows local users to control output to passwd.new via certain user input that triggers an error message.
nvd
CVE-2004-1268LOWCVSS 2.1v1.0.4v1.0.4_8+20 more2005-01-10
CVE-2004-1268 [LOW] CVE-2004-1268: lppasswd in CUPS 1.1.22 ignores write errors when modifying the CUPS passwd file, which allows local lppasswd in CUPS 1.1.22 ignores write errors when modifying the CUPS passwd file, which allows local users to corrupt the file by filling the associated file system and triggering the write errors.
nvd
CVE-2004-0558MEDIUMCVSS 5.0PoC≤ 1.1.212004-09-28
CVE-2004-0558 [MEDIUM] CVE-2004-0558: The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of service (service hang) via a certain UDP packet to the IPP port.
nvd
CVE-2003-0788MEDIUMCVSS 5.0v1.0.4v1.0.4_8+15 more2003-12-01
CVE-2003-0788 [MEDIUM] CVE-2003-0788: Unknown vulnerability in the Internet Printing Protocol (IPP) implementation in CUPS before 1.1.19 a Unknown vulnerability in the Internet Printing Protocol (IPP) implementation in CUPS before 1.1.19 allows remote attackers to cause a denial of service (CPU consumption from a "busy loop") via certain inputs to the IPP port (TCP 631).
nvd
CVE-2002-1384HIGHCVSS 7.2v1.0.4v1.0.4_8+11 more2003-01-02
CVE-2002-1384 [HIGH] CVE-2002-1384: Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allow Integer overflow in pdftops, as used in Xpdf 2.01 and earlier, xpdf-i, and CUPS before 1.1.18, allows local users to execute arbitrary code via a ColorSpace entry with a large number of elements, as demonstrated by cups-pdf.
nvd
CVE-2002-1369CRITICALCVSS 10.0v1.0.4v1.0.4_8+11 more2002-12-26
CVE-2002-1369 [CRITICAL] CVE-2002-1369: jobs.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly use the strncat jobs.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly use the strncat function call when processing the options string, which allows remote attackers to execute arbitrary code via a buffer overflow attack.
nvd
CVE-2002-1383CRITICALCVSS 10.0v1.0.4v1.0.4_8+11 more2002-12-26
CVE-2002-1383 [CRITICAL] CVE-2002-1383: Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, as demonstrated by mksun.
nvd
CVE-2002-1367CRITICALCVSS 10.0v1.0.4v1.0.4_8+11 more2002-12-26
CVE-2002-1367 [CRITICAL] CVE-2002-1367: Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to add printers wit Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to add printers without authentication via a certain UDP packet, which can then be used to perform unauthorized activities such as stealing the local root certificate for the administration server via a "need authorization" page, as demonstrated by new-coke.
nvd
CVE-2002-1371HIGHCVSS 7.5v1.0.4v1.0.4_8+11 more2002-12-26
CVE-2002-1371 [HIGH] CVE-2002-1371: filters/image-gif.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly ch filters/image-gif.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check for zero-length GIF images, which allows remote attackers to execute arbitrary code via modified chunk headers, as demonstrated by nogif.
nvd
CVE-2002-1368HIGHCVSS 7.5PoCv1.0.4v1.0.4_8+11 more2002-12-26
CVE-2002-1368 [HIGH] CVE-2002-1368: Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial o Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative arguments to be fed into memcpy() calls via HTTP requests with (1) a negative Content-Length value or (2) a negative length in a chunked transfer encoding.
nvd
CVE-2002-1366MEDIUMCVSS 6.2v1.0.4v1.1.1+7 more2002-12-26
CVE-2002-1366 [MEDIUM] CVE-2002-1366: Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows local users with lp privileges to cr Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows local users with lp privileges to create or overwrite arbitrary files via file race conditions, as demonstrated by ice-cream.
nvd
CVE-2002-0063HIGHCVSS 7.5≤ 1.1.142002-03-08
CVE-2002-0063 [HIGH] CVE-2002-0063: Buffer overflow in ippRead function of CUPS before 1.1.14 may allow attackers to execute arbitrary c Buffer overflow in ippRead function of CUPS before 1.1.14 may allow attackers to execute arbitrary code via long attribute names or language values.
nvd
CVE-2001-1332HIGHCVSS 7.5≤ 1.1.52001-05-10
CVE-2001-1332 [HIGH] CVE-2001-1332: Buffer overflows in Linux CUPS before 1.1.6 may allow remote attackers to execute arbitrary code. Buffer overflows in Linux CUPS before 1.1.6 may allow remote attackers to execute arbitrary code.
nvd
CVE-2001-1333LOWCVSS 1.2≤ 1.1.52001-05-10
CVE-2001-1333 [LOW] CVE-2001-1333: Linux CUPS before 1.1.6 does not securely handle temporary files, possibly due to a symlink vulnerab Linux CUPS before 1.1.6 does not securely handle temporary files, possibly due to a symlink vulnerability that could allow local users to overwrite files.
nvd
CVE-2001-0194CRITICALCVSS 10.0≤ 1.1.42001-05-03
CVE-2001-0194 [CRITICAL] CVE-2001-0194: Buffer overflow in httpGets function in CUPS 1.1.5 allows remote attackers to execute arbitrary comm Buffer overflow in httpGets function in CUPS 1.1.5 allows remote attackers to execute arbitrary commands via a long input line.
nvd