Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

199 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.7)0.60%—Apple CupsApple MAC OS XApple MacosDebian Linux+226/5/202217/6/2026
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.
ModificadaBaja (3.3)0.27%—Suse CupsFedoraproject Fedora5/5/202117/6/2026
A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Leap 15.2, Factory allows local attackers with control of the lp users to create files as root with 0644 permissions without the ability…
ModificadaMedia (6.5)1.2%💥 ExploitCups Easy (purchase & Inventory) Project Cups Easy (purchase & Inventory)28/1/202017/6/2026
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php.
ModificadaAlta (8.8)1.5%💥 ExploitCups Easy Project Cups Easy28/1/202017/6/2026
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php.
ModificadaCrítica (9.8)2.1%—Apple CupsDebian Linux20/12/201916/6/2026
cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system
ModificadaCrítica (9.8)5.0%—ApcupsdNetgate Pfsense3/6/201917/6/2026
Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.
ModificadaMedia (6.1)2.6%—ApcupsdNetgate Pfsense3/6/201917/6/2026
Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an XSS issue in apcupsd_status.php.
ModificadaMedia (5.9)1.8%—Apple Cups3/4/201917/6/2026
The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the web interface is enabled. This issue affected versions prior to v2.2.10.
ModificadaAlta (8.8)0.39%—CupsCanonical Ubuntu LinuxDebian Linux10/8/201817/6/2026
The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possibly use this issue to escape confinement. This flaw affects versions prior to 2.2.7-1ubuntu2.1 in Ubuntu 18.04 LTS, prior to 2.2.4-7ubuntu3.1 in Ubuntu 17.10, prior to 2.1.3-4ubuntu0.5 in Ubuntu 16.04…
ModificadaMedia (5.3)2.2%—Apple Cups26/3/201817/6/2026
The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attackers by sending print jobs with an invalid username, related to a D-Bus notification.
ModificadaAlta (7.5)2.9%—Apple CupsDebian LinuxCanonical Ubuntu Linux16/2/201817/6/2026
A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon in conjunction with DNS rebinding. The localhost.localdomain name is often resolved via a DNS server (neither the OS…
ModificadaAlta (8.8)3.7%—Cups12/1/201817/6/2026
The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to execute arbitrary code via a crafted printer name.
ModificadaAlta (8.4)0.44%—Apcupsd APC UPS Daemon16/6/201717/6/2026
In Adam Kropelin adk0212 APC UPS Daemon through 3.14.14, the default installation of APCUPSD allows a local authenticated, but unprivileged, user to run arbitrary code with elevated privileges by replacing the service executable apcupsd.exe with a malicious executable that will run with SYSTEM privileges at startup.…
ModificadaAlta (7.3)5.3%—Canonical Ubuntu LinuxDebian LinuxLinuxfoundation Cups-filtersLinuxfoundation Foomatic-filters14/4/201617/6/2026
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.
ModificadaAlta (7.5)11%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Server EUS+517/12/201517/6/2026
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.
ModificadaAlta (7.5)6.9%—Linuxfoundation Cups-filtersCanonical Ubuntu LinuxDebian Linux14/7/201517/6/2026
Integer overflow in filter/texttopdf.c in texttopdf in cups-filters before 1.0.71 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted line size in a print job, which triggers a heap-based buffer overflow.
ModificadaAlta (7.5)8.3%—Canonical Ubuntu LinuxDebian LinuxLinuxfoundation Cups-filters14/7/201517/6/2026
Heap-based buffer overflow in the WriteProlog function in filter/texttopdf.c in texttopdf in cups-filters before 1.0.70 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a small line size in a print job.
ModificadaMedia (4.3)7.2%—Cups26/6/201517/6/2026
Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter to help/.
ModificadaAlta (10)30%💥 ExploitCups26/6/201517/6/2026
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-host-name attributes, which allows remote attackers to trigger data corruption for reference-counted strings via a crafted (1) IPP_CREATE_JOB or (2) IPP_PRINT_JOB request, as…
ModificadaAlta (7.5)3.0%—Canonical Ubuntu LinuxLinuxfoundation Cups-filters24/3/201517/6/2026
The remove_bad_chars function in utils/cups-browsed.c in cups-filters before 1.0.66 allows remote IPP printers to execute arbitrary commands via consecutive shell metacharacters in the (1) model or (2) PDL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707.
ModificadaMedia (6.8)4.6%—Apple Cups19/2/201517/6/2026
Integer underflow in the cupsRasterReadPixels function in filter/raster.c in CUPS before 2.0.2 allows remote attackers to have unspecified impact via a malformed compressed raster file, which triggers a buffer overflow.
ModificadaMedia (5)2.9%—Apple CupsCanonical Ubuntu Linux29/7/201417/6/2026
The web interface in CUPS before 2.0 does not check that files have world-readable permissions, which allows remote attackers to obtains sensitive information via unspecified vectors.
ModificadaBaja (1.9)0.36%—Canonical Ubuntu LinuxApple Cups29/7/201417/6/2026
CUPS before 2.0 allows local users to read arbitrary files via a symlink attack on (1) index.html, (2) index.class, (3) index.pl, (4) index.php, (5) index.pyc, or (6) index.py.
ModificadaBaja (1.5)0.32%—Apple CupsCanonical Ubuntu Linux29/7/201417/6/2026
The web interface in CUPS 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/ and language[0] set to null. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3537.
ModificadaBaja (1.2)0.38%—Apple CupsCanonical Ubuntu LinuxFedoraproject Fedora23/7/201417/6/2026
The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/.