HP
HP Linux Imaging AND Printing Project: vulnerabilities and CVEs
HP Linux Imaging AND Printing Project has 11 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs11
Last 12 months0
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-6108 | Low (2.1) | 0.53% | — | Feb 15, 2014 | HP Linux Imaging and Printing (HPLIP) before 3.13.2 uses world-writable permissions for /var/log/hp and /var/log/hp/tmp, which allows local users to delete log files via standard filesystem operations. |
| CVE-2013-6402 | Low (2.1) | 0.49% | — | Jan 5, 2014 | base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.11 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hp-pkservice.log temporary file. |
| CVE-2013-6427 | Medium (6.8) | 4.0% | — | Dec 9, 2013 | upgrade.py in the hp-upgrade service in HP Linux Imaging and Printing (HPLIP) 3.x through 3.13.11 launches a program from an http URL, which allows man-in-the-middle attackers to execute arbitrary code by gaining… |
| CVE-2013-4325 | Medium (6.9) | 0.42% | — | Sep 23, 2013 | The check_permission_v1 function in base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.9 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended… |
| CVE-2013-0200 | Low (1.9) | 0.38% | — | Mar 6, 2013 | HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4)… |
| CVE-2011-2722 | Low (1.2) | 0.44% | — | May 25, 2012 | The send_data_to_stdout function in prnt/hpijs/hpcupsfax.cpp in HP Linux Imaging and Printing (HPLIP) 3.x before 3.11.10 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hpcupsfax.out… |
| CVE-2011-2697 | Medium (6.8) | 11% | — | Jul 29, 2011 | foomatic-rip-hplip in HP Linux Imaging and Printing (HPLIP) 3.11.5 allows remote attackers to execute arbitrary code via a crafted *FoomaticRIPCommandLine field in a .ppd file. |
| CVE-2010-4267 | High (7.5) | 11% | — | Jan 20, 2011 | Stack-based buffer overflow in the hpmud_get_pml function in io/hpmud/pml.c in Hewlett-Packard Linux Imaging and Printing (HPLIP) 1.6.7, 3.9.8, 3.10.9, and probably other versions allows remote attackers to cause a… |
| CVE-2008-2940 | High (7.2) | 0.43% | — | Aug 14, 2008 | The alert-mailing implementation in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to gain privileges and send e-mail messages from the root account via vectors related to the setalerts message, and lack… |
| CVE-2008-2941 | Medium (4.9) | 0.54% | — | Aug 14, 2008 | The hpssd message parser in hpssd.py in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to cause a denial of service (process stop) via a crafted packet, as demonstrated by sending "msg=0" to TCP port… |
| CVE-2007-5208 | High (7.6) | 67% | — | Oct 13, 2007 | hpssd in Hewlett-Packard Linux Imaging and Printing Project (hplip) 1.x and 2.x before 2.7.10 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a from address, which is not… |
Other products by HP
Intelligent Management Center · 310Hp-ux · 291Openview Network Node Manager · 80System Management Homepage · 78Instantos · 56XP7 Command View · 53Systems Insight Manager · 50Matrix Operating Environment · 34Tru64 · 32Network Node Manager I · 29Elitebook 830 G6 Firmware · 28Elitebook 840 G6 Firmware · 28