Записи cups
11 опубликованных записей вендора cups.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 90,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-20 Improper Input Validation2
- CWE-189 Numeric Errors1
- CWE-254 7PK - Security Features1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
49В плане | CVE-2015-1158Proof of concept | The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-cups · cups · CWE-254 | Критическая10,0 | — | 29,9 % | 26 июн. 2015 г. |
42В плане | CVE-2007-4351Эксплойта нет | Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a crcups · cups · CWE-189 | Критическая10,0 | — | 7,4 % | 31 окт. 2007 г. |
42В плане | CVE-2008-0882Эксплойта нет | Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon cracups · cups · CWE-119 | Критическая10,0 | — | 5,8 % | 21 февр. 2008 г. |
39Наблюдать | CVE-2008-0047Эксплойта нет | Heap-based buffer overflow in the cgiCompileSearch function in CUPS 1.3.5, and other versions including the version bundled with Apple Mac Oapple · mac os x · CWE-119 | Критическая9,3 | — | 6,8 % | 18 мар. 2008 г. |
36Наблюдать | CVE-2014-8166Эксплойта нет | The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackecups · cups · CWE-20 | Высокая8,8 | — | 3,7 % | 12 янв. 2018 г. |
35Наблюдать | CVE-2018-6553Эксплойта нет | AppArmor cupsd Sandbox Bypass Due to Use of Hard Linkscups · cups | Высокая8,8 | — | 0,4 % | 10 авг. 2018 г. |
31Наблюдать | CVE-2005-4873Эксплойта нет | Multiple stack-based buffer overflows in the phpcups PHP module for CUPS 1.1.23rc1 might allow context-dependent attackers to execute arbitrcups · cups · CWE-119 | Высокая7,5 | — | 1,9 % | 31 дек. 2005 г. |
30Наблюдать | CVE-2024-47850Эксплойта нет | CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet reCWE-400 | Высокая7,5 | — | 0,9 % | 4 окт. 2024 г. |
22Наблюдать | CVE-2007-0720Эксплойта нет | The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL cups · cups | Средняя5,0 | — | 5,3 % | 13 мар. 2007 г. |
19Наблюдать | CVE-2015-1159Эксплойта нет | Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows rcups · cups · CWE-79 | Средняя4,3 | — | 7,3 % | 26 июн. 2015 г. |
18Наблюдать | CVE-2008-1722Эксплойта нет | Multiple integer overflows in (1) filter/image-png.c and (2) filter/image-zoom.c in CUPS 1.3 allow attackers to cause a denial of service (ccups · cups · CWE-20 | Средняя4,3 | — | 2,0 % | 10 апр. 2008 г. |
- CVE-2015-115849В плане
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-
КритическаяCVSS 10,0Proof of conceptEPSS 30 %cups · cups26 июн. 2015 г.
- CVE-2007-435142В плане
Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a cr
КритическаяCVSS 10,0Эксплойта нетEPSS 7 %cups · cups31 окт. 2007 г.
- CVE-2008-088242В плане
Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon cra
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %cups · cups21 февр. 2008 г.
- CVE-2008-004739Наблюдать
Heap-based buffer overflow in the cgiCompileSearch function in CUPS 1.3.5, and other versions including the version bundled with Apple Mac O
КритическаяCVSS 9,3Эксплойта нетEPSS 7 %apple · mac os x18 мар. 2008 г.
- CVE-2014-816636Наблюдать
The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attacke
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %cups · cups12 янв. 2018 г.
- CVE-2018-655335Наблюдать
AppArmor cupsd Sandbox Bypass Due to Use of Hard Links
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %cups · cups10 авг. 2018 г.
- CVE-2005-487331Наблюдать
Multiple stack-based buffer overflows in the phpcups PHP module for CUPS 1.1.23rc1 might allow context-dependent attackers to execute arbitr
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %cups · cups31 дек. 2005 г.
- CVE-2024-4785030Наблюдать
CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet re
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %4 окт. 2024 г.
- CVE-2007-072022Наблюдать
The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL
СредняяCVSS 5,0Эксплойта нетEPSS 5 %cups · cups13 мар. 2007 г.
- CVE-2015-115919Наблюдать
Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows r
СредняяCVSS 4,3Эксплойта нетEPSS 7 %cups · cups26 июн. 2015 г.
- CVE-2008-172218Наблюдать
Multiple integer overflows in (1) filter/image-png.c and (2) filter/image-zoom.c in CUPS 1.3 allow attackers to cause a denial of service (c
СредняяCVSS 4,3Эксплойта нетEPSS 2 %cups · cups10 апр. 2008 г.