Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
199 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4) | 3.0% | — | Linuxfoundation Cups-filters | 22/6/2014 | 17/6/2026 | cups-browsed in cups-filters before 1.0.53 allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging a malformed cups-browsed.conf BrowseAllow directive that is interpreted as granting browse access to all IP addresses. | |
| Modificada | Media (4.3) | 2.9% | — | Linuxfoundation Cups-filters | 22/6/2014 | 17/6/2026 | The process_browse_data function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted packet data. | |
| Modificada | Media (5.8) | 1.1% | — | Linuxfoundation Cups-filters | 22/6/2014 | 17/6/2026 | The generate_local_queue function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the host name. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707. | |
| Modificada | Media (4.3) | 1.6% | — | Apple Cups | 18/4/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function. | |
| Modificada | Alta (8.3) | 1.2% | — | Linuxfoundation Cups-filters | 17/4/2014 | 17/6/2026 | cups-browsed in cups-filters 1.0.41 before 1.0.51 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the (1) model or (2) PDL, related to "System V interface scripts generated for queues." | |
| Modificada | Media (4.4) | 0.31% | — | Canonical Ubuntu LinuxDebian LinuxFedoraproject FedoraLinuxfoundation Cups-filters | 14/3/2014 | 17/6/2026 | The OPVPWrapper::loadDriver function in oprs/OPVPWrapper.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows local users to gain privileges via a Trojan horse driver in the same directory as the PDF file. | |
| Modificada | Media (6.8) | 3.2% | — | Canonical Ubuntu LinuxDebian LinuxFedoraproject FedoraLinuxfoundation Cups-filters | 14/3/2014 | 17/6/2026 | Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, which triggers a heap-based buffer overflow. | |
| Modificada | Media (6.8) | 3.1% | — | Linuxfoundation Cups-filtersCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora | 14/3/2014 | 17/6/2026 | Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows remote attackers to execute arbitrary code via a crafted PDF file. | |
| Modificada | Media (6.8) | 3.4% | — | Canonical Ubuntu LinuxLinuxfoundation Cups-filters | 14/3/2014 | 17/6/2026 | Multiple heap-based buffer overflows in the urftopdf filter in cups-filters 1.0.25 before 1.0.47 allow remote attackers to execute arbitrary code via a large (1) page or (2) line in a URF file. | |
| Modificada | Baja (1.2) | 0.45% | — | Apple CupsCanonical Ubuntu Linux | 26/1/2014 | 17/6/2026 | lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf. | |
| Modificada | Alta (7.2) | 2.1% | 💥 PoC | Apple Cups | 20/11/2012 | 16/6/2026 | CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface. | |
| Modificada | Media (5.8) | 1.2% | — | Cups-pk-helper Project Cups-pk-helper | 20/11/2012 | 16/6/2026 | cups-pk-helper before 0.2.3 does not properly wrap the (1) cupsGetFile and (2) cupsPutFile function calls, which allows user-assisted remote attackers to read or overwrite sensitive files using CUPS resources. | |
| Modificada | Media (5.1) | 3.9% | — | Apple Cups | 19/8/2011 | 16/6/2026 | The gif_read_lzw function in filter/image-gif.c in CUPS 1.4.8 and earlier does not properly handle the first code word in an LZW stream, which allows remote attackers to trigger a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted stream, a different vulnerability than CVE-2011-2896. | |
| Modificada | Media (5.1) | 12% | — | Swi-prologApple CupsGimp | 19/8/2011 | 16/6/2026 | The LZW decompressor in the LWZReadByte function in giftoppm.c in the David Koblas GIF decoder in PBMPLUS, as used in the gif_read_lzw function in filter/image-gif.c in CUPS before 1.4.7, the LZWReadByte function in plug-ins/common/file-gif-load.c in GIMP 2.6.11 and earlier, the LZWReadByte function in img/gifread.c… | |
| Modificada | Alta (7.5) | 2.8% | — | Apple CupsFreedesktop PopplerXpdfreader XpdfFedoraproject Fedora+7 | 5/11/2010 | 16/6/2026 | The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference. | |
| Modificada | Crítica (9.8) | 6.4% | — | Apple CupsApple MAC OS XApple MAC OS X ServerFedoraproject Fedora+9 | 5/11/2010 | 16/6/2026 | ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request. | |
| Modificada | Media (5) | 2.1% | — | Apple Cups | 22/6/2010 | 16/6/2026 | The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for authorization, which allows remote CUPS servers to cause a denial of service (infinite loop) via HTTP_UNAUTHORIZED responses. | |
| Modificada | Baja (2.6) | 0.36% | — | Apple Cups | 22/6/2010 | 16/6/2026 | The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cache/cups/job.cache file. | |
| Modificada | Media (6.8) | 4.1% | — | Apple Cups | 21/6/2010 | 16/6/2026 | The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a… | |
| Modificada | Media (4.3) | 6.5% | 💥 Exploit | Apple Cups | 17/6/2010 | 16/6/2026 | The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows… | |
| Modificada | Media (6.9) | 0.32% | — | Apple Cups | 5/3/2010 | 16/6/2026 | The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine the file that provides localized message strings, which allows local users to gain privileges via a file that contains crafted localization data with format string… | |
| Modificada | Alta (7.5) | 2.6% | — | Apple CupsApple MAC OS XApple MAC OS X ServerFedoraproject Fedora+6 | 5/3/2010 | 16/6/2026 | Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during… | |
| Modificada | Alta (7.5) | 3.9% | — | Apple CupsApple MAC OS XApple MAC OS X ServerFedoraproject Fedora+3 | 20/11/2009 | 16/6/2026 | Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number… | |
| Modificada | Media (5) | 2.6% | — | Apple Cups | 9/6/2009 | 16/6/2026 | The directory-services functionality in the scheduler in CUPS 1.1.17 and 1.1.22 allows remote attackers to cause a denial of service (cupsd daemon outage or crash) via manipulations of the timing of CUPS browse packets, related to a "pointer use-after-delete flaw." | |
| Modificada | Alta (7.5) | 20% | 💥 Exploit | Apple CupsCanonical Ubuntu LinuxDebian LinuxApple MAC OS X+3 | 9/6/2009 | 16/6/2026 | The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags. |