cups records
11 published records for vendor cups.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 90.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-20 Improper Input Validation2
- CWE-189 Numeric Errors1
- CWE-254 7PK - Security Features1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
49Plan | CVE-2015-1158Proof of concept | The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-cups · cups · CWE-254 | Critical10.0 | — | 29.9% | Jun 26, 2015 |
42Plan | CVE-2007-4351No exploit | Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a crcups · cups · CWE-189 | Critical10.0 | — | 7.4% | Oct 31, 2007 |
42Plan | CVE-2008-0882No exploit | Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon cracups · cups · CWE-119 | Critical10.0 | — | 5.8% | Feb 21, 2008 |
39Monitor | CVE-2008-0047No exploit | Heap-based buffer overflow in the cgiCompileSearch function in CUPS 1.3.5, and other versions including the version bundled with Apple Mac Oapple · mac os x · CWE-119 | Critical9.3 | — | 6.8% | Mar 18, 2008 |
36Monitor | CVE-2014-8166No exploit | The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackecups · cups · CWE-20 | High8.8 | — | 3.7% | Jan 12, 2018 |
35Monitor | CVE-2018-6553No exploit | AppArmor cupsd Sandbox Bypass Due to Use of Hard Linkscups · cups | High8.8 | — | 0.4% | Aug 10, 2018 |
31Monitor | CVE-2005-4873No exploit | Multiple stack-based buffer overflows in the phpcups PHP module for CUPS 1.1.23rc1 might allow context-dependent attackers to execute arbitrcups · cups · CWE-119 | High7.5 | — | 1.9% | Dec 31, 2005 |
30Monitor | CVE-2024-47850No exploit | CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet reCWE-400 | High7.5 | — | 0.9% | Oct 4, 2024 |
22Monitor | CVE-2007-0720No exploit | The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL cups · cups | Medium5.0 | — | 5.3% | Mar 13, 2007 |
19Monitor | CVE-2015-1159No exploit | Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows rcups · cups · CWE-79 | Medium4.3 | — | 7.3% | Jun 26, 2015 |
18Monitor | CVE-2008-1722No exploit | Multiple integer overflows in (1) filter/image-png.c and (2) filter/image-zoom.c in CUPS 1.3 allow attackers to cause a denial of service (ccups · cups · CWE-20 | Medium4.3 | — | 2.0% | Apr 10, 2008 |
- CVE-2015-115849Plan
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-
CriticalCVSS 10.0Proof of conceptEPSS 30%cups · cupsJun 26, 2015
- CVE-2007-435142Plan
Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a cr
CriticalCVSS 10.0No exploitEPSS 7%cups · cupsOct 31, 2007
- CVE-2008-088242Plan
Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon cra
CriticalCVSS 10.0No exploitEPSS 6%cups · cupsFeb 21, 2008
- CVE-2008-004739Monitor
Heap-based buffer overflow in the cgiCompileSearch function in CUPS 1.3.5, and other versions including the version bundled with Apple Mac O
CriticalCVSS 9.3No exploitEPSS 7%apple · mac os xMar 18, 2008
- CVE-2014-816636Monitor
The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attacke
HighCVSS 8.8No exploitEPSS 4%cups · cupsJan 12, 2018
- CVE-2018-655335Monitor
AppArmor cupsd Sandbox Bypass Due to Use of Hard Links
HighCVSS 8.8No exploitEPSS 0%cups · cupsAug 10, 2018
- CVE-2005-487331Monitor
Multiple stack-based buffer overflows in the phpcups PHP module for CUPS 1.1.23rc1 might allow context-dependent attackers to execute arbitr
HighCVSS 7.5No exploitEPSS 2%cups · cupsDec 31, 2005
- CVE-2024-4785030Monitor
CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet re
HighCVSS 7.5No exploitEPSS 1%Oct 4, 2024
- CVE-2007-072022Monitor
The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL
MediumCVSS 5.0No exploitEPSS 5%cups · cupsMar 13, 2007
- CVE-2015-115919Monitor
Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows r
MediumCVSS 4.3No exploitEPSS 7%cups · cupsJun 26, 2015
- CVE-2008-172218Monitor
Multiple integer overflows in (1) filter/image-png.c and (2) filter/image-zoom.c in CUPS 1.3 allow attackers to cause a denial of service (c
MediumCVSS 4.3No exploitEPSS 2%cups · cupsApr 10, 2008