CVE-2009-0577
- EPSS 3.15%
- Veröffentlicht 20.02.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in the WriteProlog function in texttops in CUPS 1.1.17 on Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow. NOTE: this issue...
CVE-2009-0032
- EPSS 0.03%
- Veröffentlicht 27.01.2009 20:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file.
CVE-2008-5377
- EPSS 0.19%
- Veröffentlicht 08.12.2008 23:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulnerability than CVE-2001-1333.
CVE-2008-5286
- EPSS 10.61%
- Veröffentlicht 01.12.2008 15:30:03
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large height value, which bypasses a validation check and triggers a buffer overflow.
- EPSS 0.29%
- Veröffentlicht 21.11.2008 02:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy and conduct CSRF attacks via the (1) add and (2) can...
CVE-2008-5183
- EPSS 1.97%
- Veröffentlicht 21.11.2008 02:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference. NOTE: this issue can be triggere...
CVE-2008-3640
- EPSS 11.53%
- Veröffentlicht 14.10.2008 21:10:35
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in the WriteProlog function in texttops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow.
CVE-2008-3639
- EPSS 10.22%
- Veröffentlicht 14.10.2008 21:10:35
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via an SGI image with malformed Run Length Encoded (RLE) data containing a small image and a large row count.
- EPSS 50.46%
- Veröffentlicht 10.10.2008 10:30:03
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and pen color opcodes that overwrite arbitrary memory.
CVE-2008-1033
- EPSS 0.2%
- Veröffentlicht 02.06.2008 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The scheduler in CUPS in Apple Mac OS X 10.5 before 10.5.3, when debug logging is enabled and a printer requires a password, allows attackers to obtain sensitive information (credentials) by reading the log data, related to "authentication environmen...