Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Rechazada | Sin puntuar | — | — | CupsAICups-filtersAI | 22/9/2026 | 22/9/2026 | Rejected reason: Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in SystemGroups (lpadmin), which is an opt-in cupsd admin role granted by a superuser. No privilege boundary is crossed. | |
| Pendiente de análisis | Alta (7.5) | 0.70% | — | LibcupsfiltersAICups-filtersAI | 20/7/2026 | 24/8/2026 | A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted… | |
| Analizada | Media (5.5) | 0.21% | — | Openprinting Cups-filters | 20/11/2025 | 17/6/2026 | cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. In versions 2.0.1 and prior, a heap-buffer-overflow vulnerability in the rastertopclx filter causes the program to crash with a segmentation fault when processing… | |
| Analizada | Baja (3.3) | 0.21% | — | Openprinting Cups-filtersOpenprinting Libcupsfilters | 12/11/2025 | 17/6/2026 | cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. In cups-filters prior to 1.28.18, by crafting a PDF file with a large `MediaBox` value, an attacker can cause CUPS-Filter 1.x’s `pdftoraster` tool to write beyond the… | |
| Analizada | Baja (3.7) | 0.45% | — | Openprinting Cups-filtersOpenprinting Libcupsfilters | 12/11/2025 | 17/6/2026 | CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as library functions to be used for the data format conversion tasks needed in Printer Applications. In CUPS-Filters versions up to and including 1.28.17 and… | |
| Modificada | Alta (8.8) | 3.7% | — | Linuxfoundation Cups-filtersFedoraproject FedoraDebian Linux | 17/5/2023 | 17/6/2026 | cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. If you use the Backend Error Handler (beh) to create an accessible network printer, this security vulnerability can cause remote code execution. `beh.c` contains the line… | |
| Modificada | Alta (7.3) | 5.3% | — | Canonical Ubuntu LinuxDebian LinuxLinuxfoundation Cups-filtersLinuxfoundation Foomatic-filters | 14/4/2016 | 17/6/2026 | Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327. | |
| Modificada | Alta (7.5) | 11% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Server EUS+5 | 17/12/2015 | 17/6/2026 | Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job. | |
| Modificada | Alta (7.5) | 6.9% | — | Linuxfoundation Cups-filtersCanonical Ubuntu LinuxDebian Linux | 14/7/2015 | 17/6/2026 | Integer overflow in filter/texttopdf.c in texttopdf in cups-filters before 1.0.71 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted line size in a print job, which triggers a heap-based buffer overflow. | |
| Modificada | Alta (7.5) | 8.3% | — | Canonical Ubuntu LinuxDebian LinuxLinuxfoundation Cups-filters | 14/7/2015 | 17/6/2026 | Heap-based buffer overflow in the WriteProlog function in filter/texttopdf.c in texttopdf in cups-filters before 1.0.70 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a small line size in a print job. | |
| Modificada | Alta (7.5) | 3.0% | — | Canonical Ubuntu LinuxLinuxfoundation Cups-filters | 24/3/2015 | 17/6/2026 | The remove_bad_chars function in utils/cups-browsed.c in cups-filters before 1.0.66 allows remote IPP printers to execute arbitrary commands via consecutive shell metacharacters in the (1) model or (2) PDL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707. | |
| Modificada | Media (4) | 3.0% | — | Linuxfoundation Cups-filters | 22/6/2014 | 17/6/2026 | cups-browsed in cups-filters before 1.0.53 allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging a malformed cups-browsed.conf BrowseAllow directive that is interpreted as granting browse access to all IP addresses. | |
| Modificada | Media (4.3) | 2.9% | — | Linuxfoundation Cups-filters | 22/6/2014 | 17/6/2026 | The process_browse_data function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted packet data. | |
| Modificada | Media (5.8) | 1.1% | — | Linuxfoundation Cups-filters | 22/6/2014 | 17/6/2026 | The generate_local_queue function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the host name. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707. | |
| Modificada | Alta (8.3) | 1.2% | — | Linuxfoundation Cups-filters | 17/4/2014 | 17/6/2026 | cups-browsed in cups-filters 1.0.41 before 1.0.51 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the (1) model or (2) PDL, related to "System V interface scripts generated for queues." | |
| Modificada | Media (4.4) | 0.31% | — | Canonical Ubuntu LinuxDebian LinuxFedoraproject FedoraLinuxfoundation Cups-filters | 14/3/2014 | 17/6/2026 | The OPVPWrapper::loadDriver function in oprs/OPVPWrapper.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows local users to gain privileges via a Trojan horse driver in the same directory as the PDF file. | |
| Modificada | Media (6.8) | 3.2% | — | Canonical Ubuntu LinuxDebian LinuxFedoraproject FedoraLinuxfoundation Cups-filters | 14/3/2014 | 17/6/2026 | Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, which triggers a heap-based buffer overflow. | |
| Modificada | Media (6.8) | 3.1% | — | Linuxfoundation Cups-filtersCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora | 14/3/2014 | 17/6/2026 | Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows remote attackers to execute arbitrary code via a crafted PDF file. | |
| Modificada | Media (6.8) | 3.4% | — | Canonical Ubuntu LinuxLinuxfoundation Cups-filters | 14/3/2014 | 17/6/2026 | Multiple heap-based buffer overflows in the urftopdf filter in cups-filters 1.0.25 before 1.0.47 allow remote attackers to execute arbitrary code via a large (1) page or (2) line in a URF file. |