Apple / Cups
56 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-26691 | cups: authorization bypass when using "local" authorization | MEDIUM | 6.7 | May 26, 2022 |
| CVE-2012-6094 | cups: 'Listen localhost:631' option not honoured correctly on IPv6-enabled systems when systemd used for CUPS socket activation | CRITICAL | 9.8 | Dec 20, 2019 |
| CVE-2018-4300 | cups: Session cookie generated by the CUPS web interface is easy to guess | HIGH | 7.3 | Apr 3, 2019 |
| CVE-2017-18248 | cups: Invalid usernames handled in scheduler/ipp.c:add_job() allow remote attackers to cause a denial of service | MEDIUM | 5.5 | Mar 26, 2018 |
| CVE-2017-18190 | cups: DNS rebinding attacks via incorrect whitelist | HIGH | 7.5 | Feb 16, 2018 |
| CVE-2014-9679 | cups: cupsRasterReadPixels buffer overflow | MEDIUM | 6.8 | Feb 19, 2015 |
| CVE-2014-5031 | cups: world-readable permissions | MEDIUM | 5.0 | Jul 29, 2014 |
| CVE-2014-5030 | cups: allows local users to read arbitrary files via a symlink attack | LOW | 1.9 | Jul 29, 2014 |
| CVE-2014-5029 | cups: Incomplete fix for CVE-2014-3537 | LOW | 1.5 | Jul 29, 2014 |
| CVE-2014-3537 | cups: insufficient checking leads to privilege escalation | LOW | 1.2 | Jul 23, 2014 |
| CVE-2014-2856 | cups: cross-site scripting flaw fixed in the 1.7.2 release | MEDIUM | 4.3 | Apr 18, 2014 |
| CVE-2013-6891 | cups: lppasswd vulnerability allows data access to unprivileged user | LOW | 1.2 | Jan 26, 2014 |
| CVE-2012-5519 | cups: privilege escalation for users of the CUPS SystemGroup group | HIGH | 7.2 | Nov 20, 2012 |
| CVE-2011-3170 | cups: gif_read_lzw() does not properly handle first code word in an LZW stream, which may lead to arbitrary code execution | MEDIUM | 5.1 | Aug 19, 2011 |
| CVE-2011-2896 | David Koblas' GIF decoder LZW decoder buffer overflow | MEDIUM | 5.1 | Aug 19, 2011 |
| CVE-2010-3702 | xpdf: uninitialized Gfx::parser pointer dereference | HIGH | 7.5 | Nov 5, 2010 |
| CVE-2010-2941 | cups: cupsd memory corruption vulnerability | CRITICAL | 9.8 | Nov 5, 2010 |
| CVE-2010-2432 | cups: DoS (infinite loop) via HTTP_UNAUTHORIZED responses STR #3518 | MEDIUM | 5.0 | Jun 22, 2010 |
| CVE-2010-2431 | cups: latent privilege escalation vulnerability | LOW | 2.6 | Jun 22, 2010 |
| CVE-2010-0542 | CUPS: texttops unchecked memory allocation failure leading to NULL pointer dereference | MEDIUM | 6.8 | Jun 21, 2010 |
| CVE-2010-1748 | cups: web interface memory disclosure | MEDIUM | 4.3 | Jun 17, 2010 |
| CVE-2010-0393 | : cups possible arbitrary code execution via suid lppasswd (STR #3482) | MEDIUM | 6.9 | Mar 5, 2010 |
| CVE-2010-0302 | cups Incomplete fix for CVE-2009-3553 | HIGH | 7.5 | Mar 5, 2010 |
| CVE-2009-3553 | cups: Use-after-free (crash) due improper reference counting in abstract file descriptors handling interface | HIGH | 7.5 | Nov 20, 2009 |
| CVE-2009-1196 | cups: DoS (stop, crash) by renewing CUPS browse packets | MEDIUM | 5.0 | Jun 9, 2009 |
Showing 1 to 25 of 56 CVEs