CVE-2022-26691
- EPSS 0.01%
- Veröffentlicht 26.05.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:54:19
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.
CVE-2012-6094
- EPSS 0.69%
- Veröffentlicht 20.12.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 01:45:48
cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system
CVE-2018-4300
- EPSS 0.38%
- Veröffentlicht 03.04.2019 18:29:06
- Zuletzt bearbeitet 21.11.2024 04:07:09
The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the web interface is enabled. This issue affected versions prior to v2.2.10.
CVE-2017-18248
- EPSS 1.14%
- Veröffentlicht 26.03.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:40
The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attackers by sending print jobs with an invalid username, related to a D-Bus notification.
CVE-2017-18190
- EPSS 0.7%
- Veröffentlicht 16.02.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:31
A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon in conjunction with DNS rebinding. The localhost....
CVE-2014-9679
- EPSS 7.36%
- Veröffentlicht 19.02.2015 15:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer underflow in the cupsRasterReadPixels function in filter/raster.c in CUPS before 2.0.2 allows remote attackers to have unspecified impact via a malformed compressed raster file, which triggers a buffer overflow.
- EPSS 1.62%
- Veröffentlicht 29.07.2014 14:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The web interface in CUPS before 2.0 does not check that files have world-readable permissions, which allows remote attackers to obtains sensitive information via unspecified vectors.
CVE-2014-5030
- EPSS 0.05%
- Veröffentlicht 29.07.2014 14:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
CUPS before 2.0 allows local users to read arbitrary files via a symlink attack on (1) index.html, (2) index.class, (3) index.pl, (4) index.php, (5) index.pyc, or (6) index.py.
CVE-2014-5029
- EPSS 0.05%
- Veröffentlicht 29.07.2014 14:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The web interface in CUPS 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/ and language[0] set to null. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-...
CVE-2014-3537
- EPSS 0.05%
- Veröffentlicht 23.07.2014 14:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/.