Skip to main content

Vendor/product archive

apple / cups CVEs

Beta · best-effort

56 CVEs tagged to apple / cups6 Critical, 11 High, 33 Medium, 6 Low, 0 Unrated.

CVE-2012-6094

Published Dec 20, 2019

cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-4300

Published Apr 3, 2019

The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the web interface is enabled. Th…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18248

Published Mar 26, 2018

The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attackers by sending print jobs with an invalid username, rel…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-5031

Published Jul 29, 2014

The web interface in CUPS before 2.0 does not check that files have world-readable permissions, which allows remote attackers to obtains sensitive information via unspecified vect…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-5030

Published Jul 29, 2014

CUPS before 2.0 allows local users to read arbitrary files via a symlink attack on (1) index.html, (2) index.class, (3) index.pl, (4) index.php, (5) index.pyc, or (6) index.py.

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-5029

Published Jul 29, 2014

The web interface in CUPS 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/ and language[0] set to null. NOT…

CVSS 1.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-2856

Published Apr 18, 2014

Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML vi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6891

Published Jan 26, 2014

lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink a…

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-5519

Published Nov 20, 2012

CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, wh…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3170

Published Aug 19, 2011

The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does not properly handle the first code word in an LZW stream, which allows remote attackers to trigger a…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3702

Published Nov 5, 2010

The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows co…

CVSS 7.5 · High

CVE-2010-2941

Published Nov 5, 2010

ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of…

CVSS 9.8 · Critical

CVE-2010-2432

Published Jun 22, 2010

The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for authorization, which allows remo…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2431

Published Jun 22, 2010

The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.ca…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-0542

Published Jun 21, 2010

The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0393

Published Mar 5, 2010

The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine the file that provides localize…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0302

Published Mar 5, 2010

Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4,…

CVSS 7.5 · High

CVE-2009-1196

Published Jun 9, 2009

The directory-services functionality in the scheduler in CUPS 1.1.17 and 1.1.22 allows remote attackers to cause a denial of service (cupsd daemon outage or crash) via manipulatio…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 56 CVEsPage 1 of 3