Search CVE reports


Toggle filters

41 – 50 of 135 results


CVE-2014-8166

Low priority
Ignored

The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to execute arbitrary code via a crafted printer name.

1 affected package

cups

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cups Not affected
Show less packages

CVE-2014-5031

Medium priority
Fixed

The web interface in CUPS before 2.0 does not check that files have world-readable permissions, which allows remote attackers to obtains sensitive information via unspecified vectors.

1 affected package

cups

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cups
Show less packages

CVE-2014-5030

Medium priority
Fixed

CUPS before 2.0 allows local users to read arbitrary files via a symlink attack on (1) index.html, (2) index.class, (3) index.pl, (4) index.php, (5) index.pyc, or (6) index.py.

1 affected package

cups

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cups
Show less packages

CVE-2014-5029

Medium priority
Fixed

The web interface in CUPS 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/ and language[0] set to null. NOTE: this vulnerability exists because of...

1 affected package

cups

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cups
Show less packages

CVE-2014-4338

Low priority
Fixed

cups-browsed in cups-filters before 1.0.53 allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging a malformed cups-browsed.conf BrowseAllow directive that is interpreted as...

1 affected package

cups-filters

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cups-filters
Show less packages

CVE-2014-4337

Medium priority
Fixed

The process_browse_data function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted packet data.

1 affected package

cups-filters

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cups-filters
Show less packages

CVE-2014-4336

Medium priority
Fixed

The generate_local_queue function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the host name. NOTE: this vulnerability...

1 affected package

cups-filters

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cups-filters
Show less packages

CVE-2014-3537

Medium priority
Fixed

The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/.

1 affected package

cups

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cups
Show less packages

CVE-2014-2856

Medium priority
Fixed

Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.

1 affected package

cups

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cups
Show less packages

CVE-2014-2707

High priority
Fixed

cups-browsed in cups-filters 1.0.41 before 1.0.51 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the (1) model or (2) PDL, related to "System V interface scripts generated for queues."

1 affected package

cups-filters

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cups-filters
Show less packages