Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown

CVE-2020-8425

Disclosure Date: January 28, 2020 (last updated February 21, 2025)
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php.
Attacker Value
Unknown

CVE-2020-8424

Disclosure Date: January 28, 2020 (last updated February 21, 2025)
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php.
Attacker Value
Unknown

CVE-2019-12585

Disclosure Date: June 03, 2019 (last updated November 27, 2024)
Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.
0
Attacker Value
Unknown

CVE-2019-12584

Disclosure Date: June 03, 2019 (last updated November 27, 2024)
Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an XSS issue in apcupsd_status.php.
0
Attacker Value
Unknown

AppArmor cupsd Sandbox Bypass Due to Use of Hard Links

Disclosure Date: August 10, 2018 (last updated November 27, 2024)
The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possibly use this issue to escape confinement. This flaw affects versions prior to 2.2.7-1ubuntu2.1 in Ubuntu 18.04 LTS, prior to 2.2.4-7ubuntu3.1 in Ubuntu 17.10, prior to 2.1.3-4ubuntu0.5 in Ubuntu 16.04 LTS, and prior to 1.7.2-0ubuntu1.10 in Ubuntu 14.04 LTS.
0
Attacker Value
Unknown

CVE-2014-8166

Disclosure Date: January 12, 2018 (last updated November 26, 2024)
The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to execute arbitrary code via a crafted printer name.
Attacker Value
Unknown

CVE-2017-7884

Disclosure Date: June 16, 2017 (last updated November 26, 2024)
In Adam Kropelin adk0212 APC UPS Daemon through 3.14.14, the default installation of APCUPSD allows a local authenticated, but unprivileged, user to run arbitrary code with elevated privileges by replacing the service executable apcupsd.exe with a malicious executable that will run with SYSTEM privileges at startup. This occurs because of "RW NT AUTHORITY\Authenticated Users" permissions for %SYSTEMDRIVE%\apcupsd\bin\apcupsd.exe.
0
Attacker Value
Unknown

CVE-2015-1158

Disclosure Date: June 26, 2015 (last updated October 05, 2023)
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-host-name attributes, which allows remote attackers to trigger data corruption for reference-counted strings via a crafted (1) IPP_CREATE_JOB or (2) IPP_PRINT_JOB request, as demonstrated by replacing the configuration file and consequently executing arbitrary code.
0
Attacker Value
Unknown

CVE-2015-1159

Disclosure Date: June 26, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter to help/.
0
Attacker Value
Unknown

CVE-2012-4510

Disclosure Date: November 20, 2012 (last updated October 05, 2023)
cups-pk-helper before 0.2.3 does not properly wrap the (1) cupsGetFile and (2) cupsPutFile function calls, which allows user-assisted remote attackers to read or overwrite sensitive files using CUPS resources.
0