← Back

Cups

cups

Vendor: Apple • 56 CVEs

CVEs (56)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Apple
DebianFedoraproject+1 more
6Cups
CupsDebian Linux+3 more
Nov 21, 2024
May 26, 2022
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.
2Apple
Debian
2Cups
Debian Linux
Nov 21, 2024
Dec 20, 2019
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system
1Apple
1Cups
Nov 21, 2024
Apr 3, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the web interface is enabled. This issue affected versions prior to v2.2....Show more
The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the web interface is enabled. This issue affected versions prior to v2.2.10.Show less
1Apple
1Cups
Nov 21, 2024
Mar 26, 2018
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attackers by sending print jobs with an invalid username, related to a D-Bus notification.
3Apple
CanonicalDebian
3Cups
Debian LinuxUbuntu Linux
Nov 21, 2024
Feb 16, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon in conjunction with...Show more
A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon in conjunction with DNS rebinding. The localhost.localdomain name is often resolved via a DNS server (neither the OS nor the web browser is responsible for ensuring that localhost.localdomain is 127.0.0.1).Show less
1Apple
1Cups
May 6, 2026
Feb 19, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer underflow in the cupsRasterReadPixels function in filter/raster.c in CUPS before 2.0.2 allows remote attackers to have unspecified impact via a malformed compressed raster file, which triggers a buffer overflow.
2Apple
Canonical
2Cups
Ubuntu Linux
May 6, 2026
Jul 29, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The web interface in CUPS before 2.0 does not check that files have world-readable permissions, which allows remote attackers to obtains sensitive information via unspecified vectors.
2Apple
Canonical
2Cups
Ubuntu Linux
May 6, 2026
Jul 29, 2014
N/A· v4
N/A· v3
1.9 LOW· v2
CUPS before 2.0 allows local users to read arbitrary files via a symlink attack on (1) index.html, (2) index.class, (3) index.pl, (4) index.php, (5) index.pyc, or (6) index.py.
2Apple
Canonical
2Cups
Ubuntu Linux
May 6, 2026
Jul 29, 2014
N/A· v4
N/A· v3
1.5 LOW· v2
The web interface in CUPS 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/ and language[0] set to null. NOTE: this vulnerability exists because of a...Show more
The web interface in CUPS 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/ and language[0] set to null. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3537.Show less
3Apple
CanonicalFedoraproject
3Cups
FedoraUbuntu Linux
May 6, 2026
Jul 23, 2014
N/A· v4
N/A· v3
1.2 LOW· v2
The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/.
1Apple
1Cups
May 6, 2026
Apr 18, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_ab...Show more
Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.Show less
2Apple
Canonical
2Cups
Ubuntu Linux
Apr 29, 2026
Jan 26, 2014
N/A· v4
N/A· v3
1.2 LOW· v2
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.
1Apple
1Cups
Apr 29, 2026
Nov 20, 2012
N/A· v4
N/A· v3
7.2 HIGH· v2
CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin gro...Show more
CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.Show less
1Apple
1Cups
Apr 29, 2026
Aug 19, 2011
N/A· v4
N/A· v3
5.1 MEDIUM· v2
The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does not properly handle the first code word in an LZW stream, which allows remote attackers to trigger a heap-based buffer overflow, and possibly...Show more
The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does not properly handle the first code word in an LZW stream, which allows remote attackers to trigger a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted stream, a different vulnerability than CVE-2011-2896.Show less
3Apple
GimpSwi Prolog
3Cups
GimpSwi Prolog
Apr 29, 2026
Aug 19, 2011
N/A· v4
N/A· v3
5.1 MEDIUM· v2
The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte function in plug...Show more
The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte function in plug-ins/common/file-gif-load.c in GIMP 2.6.11 and earlier, the LZWReadByte function in img/gifread.c in XPCE in SWI-Prolog 5.10.4 and earlier, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows remote attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2895.Show less
9Apple
CanonicalDebian+6 more
11Cups
Debian LinuxEnterprise Linux Desktop+8 more
Apr 29, 2026
Nov 5, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a deni...Show more
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference.Show less
7Apple
CanonicalDebian+4 more
13Cups
Debian LinuxEnterprise Linux+10 more
Apr 29, 2026
Nov 5, 2010
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application c...Show more
ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.Show less
1Apple
1Cups
Apr 29, 2026
Jun 22, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for authorization, which allows remote CUPS servers to cause a denial of serv...Show more
The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for authorization, which allows remote CUPS servers to cause a denial of service (infinite loop) via HTTP_UNAUTHORIZED responses.Show less
1Apple
1Cups
Apr 29, 2026
Jun 22, 2010
N/A· v4
N/A· v3
2.6 LOW· v2
The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cache/cups/job.cache file...Show more
The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cache/cups/job.cache file.Show less
1Apple
1Cups
Apr 29, 2026
Jun 21, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (...Show more
The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.Show less