Apple

Cups

56 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.15%
  • Published 20.02.2009 19:30:00
  • Last modified 09.04.2025 00:30:58

Integer overflow in the WriteProlog function in texttops in CUPS 1.1.17 on Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow. NOTE: this issue...

  • EPSS 0.03%
  • Published 27.01.2009 20:30:00
  • Last modified 09.04.2025 00:30:58

CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file.

Exploit
  • EPSS 0.19%
  • Published 08.12.2008 23:30:00
  • Last modified 09.04.2025 00:30:58

pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulnerability than CVE-2001-1333.

  • EPSS 10.61%
  • Published 01.12.2008 15:30:03
  • Last modified 09.04.2025 00:30:58

Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large height value, which bypasses a validation check and triggers a buffer overflow.

Exploit
  • EPSS 0.29%
  • Published 21.11.2008 02:30:00
  • Last modified 09.04.2025 00:30:58

The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy and conduct CSRF attacks via the (1) add and (2) can...

  • EPSS 1.97%
  • Published 21.11.2008 02:30:00
  • Last modified 09.04.2025 00:30:58

cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference. NOTE: this issue can be triggere...

  • EPSS 11.53%
  • Published 14.10.2008 21:10:35
  • Last modified 09.04.2025 00:30:58

Integer overflow in the WriteProlog function in texttops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow.

  • EPSS 10.22%
  • Published 14.10.2008 21:10:35
  • Last modified 09.04.2025 00:30:58

Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via an SGI image with malformed Run Length Encoded (RLE) data containing a small image and a large row count.

Exploit
  • EPSS 50.46%
  • Published 10.10.2008 10:30:03
  • Last modified 09.04.2025 00:30:58

The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and pen color opcodes that overwrite arbitrary memory.

  • EPSS 0.2%
  • Published 02.06.2008 21:30:00
  • Last modified 09.04.2025 00:30:58

The scheduler in CUPS in Apple Mac OS X 10.5 before 10.5.3, when debug logging is enabled and a printer requires a password, allows attackers to obtain sensitive information (credentials) by reading the log data, related to "authentication environmen...