Skip to content
Noroxi

cups records

11 published records for vendor cups.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
5
With a fix record
90.9%
Median publish → KEV
No record has entered KEV

All records

11 records
  • The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-

    CriticalCVSS 10.0Proof of conceptEPSS 30%

    cups · cupsJun 26, 2015

  • Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a cr

    CriticalCVSS 10.0No exploitEPSS 7%

    cups · cupsOct 31, 2007

  • Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon cra

    CriticalCVSS 10.0No exploitEPSS 6%

    cups · cupsFeb 21, 2008

  • CVE-2008-0047
    39Monitor

    Heap-based buffer overflow in the cgiCompileSearch function in CUPS 1.3.5, and other versions including the version bundled with Apple Mac O

    CriticalCVSS 9.3No exploitEPSS 7%

    apple · mac os xMar 18, 2008

  • CVE-2014-8166
    36Monitor

    The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attacke

    HighCVSS 8.8No exploitEPSS 4%

    cups · cupsJan 12, 2018

  • CVE-2018-6553
    35Monitor

    AppArmor cupsd Sandbox Bypass Due to Use of Hard Links

    HighCVSS 8.8No exploitEPSS 0%

    cups · cupsAug 10, 2018

  • CVE-2005-4873
    31Monitor

    Multiple stack-based buffer overflows in the phpcups PHP module for CUPS 1.1.23rc1 might allow context-dependent attackers to execute arbitr

    HighCVSS 7.5No exploitEPSS 2%

    cups · cupsDec 31, 2005

  • CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet re

    HighCVSS 7.5No exploitEPSS 1%

    Oct 4, 2024

  • CVE-2007-0720
    22Monitor

    The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL

    MediumCVSS 5.0No exploitEPSS 5%

    cups · cupsMar 13, 2007

  • CVE-2015-1159
    19Monitor

    Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows r

    MediumCVSS 4.3No exploitEPSS 7%

    cups · cupsJun 26, 2015

  • CVE-2008-1722
    18Monitor

    Multiple integer overflows in (1) filter/image-png.c and (2) filter/image-zoom.c in CUPS 1.3 allow attackers to cause a denial of service (c

    MediumCVSS 4.3No exploitEPSS 2%

    cups · cupsApr 10, 2008