Show filters
38 Total Results
Displaying 21-30 of 38
Sort by:
Attacker Value
Unknown

CVE-2009-0799

Disclosure Date: April 23, 2009 (last updated October 04, 2023)
The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers an out-of-bounds read.
0
Attacker Value
Unknown

CVE-2009-0195

Disclosure Date: April 23, 2009 (last updated October 04, 2023)
Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrary code via a PDF file with crafted JBIG2 symbol dictionary segments.
0
Attacker Value
Unknown

CVE-2009-1180

Disclosure Date: April 23, 2009 (last updated October 04, 2023)
The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data.
0
Attacker Value
Unknown

CVE-2008-5377

Disclosure Date: December 08, 2008 (last updated October 04, 2023)
pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulnerability than CVE-2001-1333.
0
Attacker Value
Unknown

CVE-2008-5286

Disclosure Date: December 01, 2008 (last updated October 04, 2023)
Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large height value, which bypasses a validation check and triggers a buffer overflow.
0
Attacker Value
Unknown

CVE-2008-5184

Disclosure Date: November 21, 2008 (last updated October 04, 2023)
The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy and conduct CSRF attacks via the (1) add and (2) cancel RSS subscription functions.
0
Attacker Value
Unknown

CVE-2008-3640

Disclosure Date: October 14, 2008 (last updated October 04, 2023)
Integer overflow in the WriteProlog function in texttops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2008-3639

Disclosure Date: October 14, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via an SGI image with malformed Run Length Encoded (RLE) data containing a small image and a large row count.
0
Attacker Value
Unknown

CVE-2008-3641

Disclosure Date: October 10, 2008 (last updated October 04, 2023)
The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and pen color opcodes that overwrite arbitrary memory.
0
Attacker Value
Unknown

CVE-2008-1722

Disclosure Date: April 10, 2008 (last updated October 04, 2023)
Multiple integer overflows in (1) filter/image-png.c and (2) filter/image-zoom.c in CUPS 1.3 allow attackers to cause a denial of service (crash) and trigger memory corruption, as demonstrated via a crafted PNG image.
0