CVEs (56)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values...Show more |
The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine the file that provides localized message strings, which allows local use...Show more |
4Apple CanonicalFedoraproject+1 more10Cups Enterprise LinuxEnterprise Linux Desktop+7 moreApr 29, 2026 Mar 5, 2010 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows rem...Show more |
5Apple CanonicalDebian+2 more7Cups Debian LinuxEnterprise Linux+4 moreApr 23, 2026 Nov 20, 2009 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a de...Show more |
The directory-services functionality in the scheduler in CUPS 1.1.17 and 1.1.22 allows remote attackers to cause a denial of service (cupsd daemon outage or crash) via manipulations of the timing of CUPS browse packets,...Show more |
5Apple CanonicalDebian+2 more7Cups Debian LinuxLinux Enterprise+4 moreApr 23, 2026 Jun 9, 2009 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and da...Show more |
Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the pdftops filter in CUPS 1.1.17, 1.1.22, and 1.3.7, GPdf, and kdegraphics KPDF, allow remote attackers to cause a denial of service (applicatio...Show more |
The web interface for CUPS before 1.3.10 does not validate the HTTP Host header in a client request, which makes it easier for remote attackers to conduct DNS rebinding attacks. |
4Apple FoolabsGlyphandcog+1 more4Cups PopplerXpdf+1 moreApr 23, 2026 Apr 23, 2009 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted PDF file. |
4Apple FoolabsGlyphandcog+1 more4Cups PopplerXpdf+1 moreApr 23, 2026 Apr 23, 2009 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file. |
4Apple FoolabsGlyphandcog+1 more4Cups PopplerXpdf+1 moreApr 23, 2026 Apr 23, 2009 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a NULL po...Show more |
4Apple FoolabsGlyphandcog+1 more4Cups PopplerXpdf+1 moreApr 23, 2026 Apr 23, 2009 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid da...Show more |
4Apple FoolabsGlyphandcog+1 more4Cups PopplerXpdf+1 moreApr 23, 2026 Apr 23, 2009 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file. |
4Apple FoolabsGlyphandcog+1 more4Cups PopplerXpdf+1 moreApr 23, 2026 Apr 23, 2009 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF fil...Show more |
4Apple FoolabsGlyphandcog+1 more4Cups PopplerXpdf+1 moreApr 23, 2026 Apr 23, 2009 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers an out-of...Show more |
3Apple FoolabsGlyphandcog3Cups XpdfXpdfreaderApr 23, 2026 Apr 23, 2009 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrary code via a PDF file with crafted JBIG2 symbol dictionary segments. |
4Apple FoolabsGlyphandcog+1 more4Cups PopplerXpdf+1 moreApr 23, 2026 Apr 23, 2009 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a free of uninitialized memory. |
Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a crafted TIFF image, which is no...Show more |
3Apple FoolabsGlyphandcog3Cups XpdfXpdfreaderApr 23, 2026 Apr 23, 2009 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) J...Show more |
3Apple FoolabsGlyphandcog3Cups XpdfXpdfreaderApr 23, 2026 Apr 23, 2009 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JB...Show more |