Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown
CVE-2020-8425
Disclosure Date: January 28, 2020 (last updated February 21, 2025)
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php.
0
Attacker Value
Unknown
CVE-2020-8424
Disclosure Date: January 28, 2020 (last updated February 21, 2025)
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php.
0
Attacker Value
Unknown
CVE-2019-12585
Disclosure Date: June 03, 2019 (last updated November 27, 2024)
Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.
0
Attacker Value
Unknown
CVE-2019-12584
Disclosure Date: June 03, 2019 (last updated November 27, 2024)
Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an XSS issue in apcupsd_status.php.
0
Attacker Value
Unknown
AppArmor cupsd Sandbox Bypass Due to Use of Hard Links
Disclosure Date: August 10, 2018 (last updated November 27, 2024)
The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possibly use this issue to escape confinement. This flaw affects versions prior to 2.2.7-1ubuntu2.1 in Ubuntu 18.04 LTS, prior to 2.2.4-7ubuntu3.1 in Ubuntu 17.10, prior to 2.1.3-4ubuntu0.5 in Ubuntu 16.04 LTS, and prior to 1.7.2-0ubuntu1.10 in Ubuntu 14.04 LTS.
0
Attacker Value
Unknown
CVE-2014-8166
Disclosure Date: January 12, 2018 (last updated November 26, 2024)
The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to execute arbitrary code via a crafted printer name.
0
Attacker Value
Unknown
CVE-2017-7884
Disclosure Date: June 16, 2017 (last updated November 26, 2024)
In Adam Kropelin adk0212 APC UPS Daemon through 3.14.14, the default installation of APCUPSD allows a local authenticated, but unprivileged, user to run arbitrary code with elevated privileges by replacing the service executable apcupsd.exe with a malicious executable that will run with SYSTEM privileges at startup. This occurs because of "RW NT AUTHORITY\Authenticated Users" permissions for %SYSTEMDRIVE%\apcupsd\bin\apcupsd.exe.
0
Attacker Value
Unknown
CVE-2015-1158
Disclosure Date: June 26, 2015 (last updated October 05, 2023)
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-host-name attributes, which allows remote attackers to trigger data corruption for reference-counted strings via a crafted (1) IPP_CREATE_JOB or (2) IPP_PRINT_JOB request, as demonstrated by replacing the configuration file and consequently executing arbitrary code.
0
Attacker Value
Unknown
CVE-2015-1159
Disclosure Date: June 26, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter to help/.
0
Attacker Value
Unknown
CVE-2012-4510
Disclosure Date: November 20, 2012 (last updated October 05, 2023)
cups-pk-helper before 0.2.3 does not properly wrap the (1) cupsGetFile and (2) cupsPutFile function calls, which allows user-assisted remote attackers to read or overwrite sensitive files using CUPS resources.
0