7.5

CVE-2008-5183

cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference.  NOTE: this issue can be triggered remotely by leveraging CVE-2008-5184.

Data is provided by the National Vulnerability Database (NVD)
AppleCups Version <= 1.3.9
ApplemacOS X Version < 10.5.6
ApplemacOS X Server Version < 10.5.6
OpensuseOpensuse Version11.0
DebianDebian Linux Version5.0
DebianDebian Linux Version6.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.97% 0.819
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

http://www.securityfocus.com/bid/32419
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id?1021396
Third Party Advisory
Broken Link
VDB Entry
https://www.exploit-db.com/exploits/7150
Third Party Advisory
VDB Entry