Search CVE reports


Toggle filters

81 – 90 of 135 results


CVE-2009-0949

Medium priority
Fixed

The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and...

2 affected packages

cups, cupsys

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cups
cupsys
Show less packages

CVE-2009-0800

Medium priority

Some fixes available 35 of 78

Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.

14 affected packages

cups, evince, gpdf, kdegraphics, koffice...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cups Not affected Not affected Not affected
evince Not affected Not affected Not affected
gpdf Not in release Not in release Not in release
kdegraphics Not in release Not in release Not in release
koffice Not in release Not in release Not in release
pdftohtml Not in release Not in release Not in release
poppler Fixed Fixed Fixed
tetex-bin Not in release Not in release Not in release
texlive-bin Not affected Not affected Not affected
xpdf Not affected Not in release Not affected
ipe Not affected Not affected Not affected
libextractor Not affected Not affected Not affected
cupsys Not in release Not in release Not in release
pdfkit.framework Not in release Not in release Not in release
Show all 14 packages Show less packages

CVE-2009-0799

Medium priority

Some fixes available 35 of 78

The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers an out-of-bounds read.

14 affected packages

xpdf, cups, cupsys, evince, gpdf...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
xpdf Not affected Not in release Not affected
cups Not affected Not affected Not affected
cupsys Not in release Not in release Not in release
evince Not affected Not affected Not affected
gpdf Not in release Not in release Not in release
ipe Not affected Not affected Not affected
kdegraphics Not in release Not in release Not in release
koffice Not in release Not in release Not in release
pdfkit.framework Not in release Not in release Not in release
pdftohtml Not in release Not in release Not in release
poppler Fixed Fixed Fixed
tetex-bin Not in release Not in release Not in release
texlive-bin Not affected Not affected Not affected
libextractor Not affected Not affected Not affected
Show all 14 packages Show less packages

CVE-2009-0791

Medium priority
Not affected

Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the pdftops filter in CUPS 1.1.17, 1.1.22, and 1.3.7, GPdf, and kdegraphics KPDF, allow remote attackers to cause a denial of service (application crash)...

2 affected packages

cups, cupsys

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cups
cupsys
Show less packages

CVE-2009-0166

Medium priority

Some fixes available 35 of 78

The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a free of uninitialized memory.

14 affected packages

kdegraphics, gpdf, cups, cupsys, evince...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kdegraphics Not in release Not in release Not in release
gpdf Not in release Not in release Not in release
cups Not affected Not affected Not affected
cupsys Not in release Not in release Not in release
evince Not affected Not affected Not affected
ipe Not affected Not affected Not affected
koffice Not in release Not in release Not in release
libextractor Not affected Not affected Not affected
pdfkit.framework Not in release Not in release Not in release
pdftohtml Not in release Not in release Not in release
poppler Fixed Fixed Fixed
tetex-bin Not in release Not in release Not in release
texlive-bin Not affected Not affected Not affected
xpdf Not affected Not in release Not affected
Show all 14 packages Show less packages

CVE-2009-0164

Low priority
Ignored

The web interface for CUPS before 1.3.10 does not validate the HTTP Host header in a client request, which makes it easier for remote attackers to conduct DNS rebinding attacks.

2 affected packages

cups, cupsys

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cups
cupsys
Show less packages

CVE-2009-0163

Medium priority
Fixed

Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a crafted TIFF image, which is not properly...

2 affected packages

cups, cupsys

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cups
cupsys
Show less packages

CVE-2009-0147

Medium priority

Some fixes available 21 of 58

Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to...

14 affected packages

gpdf, cups, cupsys, evince, ipe...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpdf
cups
cupsys
evince
ipe
kdegraphics
koffice
libextractor
pdfkit.framework
pdftohtml
poppler
tetex-bin
texlive-bin
xpdf
Show all 14 packages Show less packages

CVE-2009-0146

Medium priority

Some fixes available 21 of 51

Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to...

14 affected packages

gpdf, evince, poppler, texlive-bin, xpdf...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpdf
evince
poppler
texlive-bin
xpdf
cups
cupsys
ipe
kdegraphics
koffice
libextractor
pdfkit.framework
pdftohtml
tetex-bin
Show all 14 packages Show less packages

CVE-2009-0032

Medium priority
Not affected

CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file.

2 affected packages

cups, cupsys

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cups
cupsys
Show less packages