Search CVE reports
11 – 20 of 77 results
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote...
2 affected packages
cups, cupsys
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cups | — | — | — | — |
cupsys | — | — | — | — |
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a denial of...
2 affected packages
cups, cupsys
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cups | — | — | — | — |
cupsys | — | — | — | — |
Some fixes available 5 of 6
The web interface in CUPS before 1.4.2, as used on Apple Mac OS X before 10.6.2 and other platforms, does not properly handle (1) HTTP headers and (2) HTML templates, which allows remote attackers to conduct cross-site scripting...
2 affected packages
cups, cupsys
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cups | — | — | — | — |
cupsys | — | — | — | — |
Heap-based buffer overflow in the USB backend in CUPS in Apple Mac OS X 10.5.8 allows local users to gain privileges via unspecified vectors.
2 affected packages
cups, cupsys
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cups | — | — | — | — |
cupsys | — | — | — | — |
The directory-services functionality in the scheduler in CUPS 1.1.17 and 1.1.22 allows remote attackers to cause a denial of service (cupsd daemon outage or crash) via manipulations of the timing of CUPS browse packets, related to...
2 affected packages
cups, cupsys
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cups | — | — | — | — |
cupsys | — | — | — | — |
Some fixes available 34 of 74
Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF, allows remote attackers to...
14 affected packages
koffice, xpdf, libextractor, cups, cupsys...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
koffice | — | Not in release | Not in release | Not in release |
xpdf | — | Not affected | Not in release | Not affected |
libextractor | — | Not affected | Not affected | Not affected |
cups | — | Not affected | Not affected | Not affected |
cupsys | — | Not in release | Not in release | Not in release |
evince | — | Not affected | Not affected | Not affected |
gpdf | — | Not in release | Not in release | Not in release |
ipe | — | Not affected | Not affected | Not affected |
kdegraphics | — | Not in release | Not in release | Not in release |
pdfkit.framework | — | Not in release | Not in release | Not in release |
pdftohtml | — | Not in release | Not in release | Not in release |
poppler | — | Fixed | Fixed | Fixed |
tetex-bin | — | Not in release | Not in release | Not in release |
texlive-bin | — | Not affected | Not affected | Not affected |
Some fixes available 5 of 19
Integer overflow in the JBIG2 decoding feature in Poppler before 0.10.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to CairoOutputDev (CairoOutputDev.cc).
14 affected packages
cupsys, cups, evince, gpdf, ipe...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cupsys | — | — | — | — |
cups | — | — | — | — |
evince | — | — | — | — |
gpdf | — | — | — | — |
ipe | — | — | — | — |
kdegraphics | — | — | — | — |
koffice | — | — | — | — |
libextractor | — | — | — | — |
pdfkit.framework | — | — | — | — |
pdftohtml | — | — | — | — |
poppler | — | — | — | — |
tetex-bin | — | — | — | — |
texlive-bin | — | — | — | — |
xpdf | — | — | — | — |
Some fixes available 34 of 76
The JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted PDF file.
14 affected packages
cups, cupsys, evince, gpdf, ipe...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cups | — | Not affected | Not affected | Not affected |
cupsys | — | Not in release | Not in release | Not in release |
evince | — | Not affected | Not affected | Not affected |
gpdf | — | Not in release | Not in release | Not in release |
ipe | — | Not affected | Not affected | Not affected |
kdegraphics | — | Not in release | Not in release | Not in release |
koffice | — | Not in release | Not in release | Not in release |
libextractor | — | Not affected | Not affected | Not affected |
pdfkit.framework | — | Not in release | Not in release | Not in release |
pdftohtml | — | Not in release | Not in release | Not in release |
poppler | — | Fixed | Fixed | Fixed |
tetex-bin | — | Not in release | Not in release | Not in release |
texlive-bin | — | Not affected | Not affected | Not affected |
xpdf | — | Not affected | Not in release | Not affected |
Some fixes available 34 of 76
Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.
14 affected packages
cupsys, gpdf, cups, evince, ipe...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cupsys | — | Not in release | Not in release | Not in release |
gpdf | — | Not in release | Not in release | Not in release |
cups | — | Not affected | Not affected | Not affected |
evince | — | Not affected | Not affected | Not affected |
ipe | — | Not affected | Not affected | Not affected |
kdegraphics | — | Not in release | Not in release | Not in release |
koffice | — | Not in release | Not in release | Not in release |
libextractor | — | Not affected | Not affected | Not affected |
pdfkit.framework | — | Not in release | Not in release | Not in release |
pdftohtml | — | Not in release | Not in release | Not in release |
poppler | — | Fixed | Fixed | Fixed |
tetex-bin | — | Not in release | Not in release | Not in release |
texlive-bin | — | Not affected | Not affected | Not affected |
xpdf | — | Not affected | Not in release | Not affected |
Some fixes available 35 of 78
The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a NULL pointer dereference.
14 affected packages
cups, libextractor, cupsys, evince, gpdf...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
cups | — | Not affected | Not affected | Not affected |
libextractor | — | Not affected | Not affected | Not affected |
cupsys | — | Not in release | Not in release | Not in release |
evince | — | Not affected | Not affected | Not affected |
gpdf | — | Not in release | Not in release | Not in release |
ipe | — | Not affected | Not affected | Not affected |
kdegraphics | — | Not in release | Not in release | Not in release |
koffice | — | Not in release | Not in release | Not in release |
pdfkit.framework | — | Not in release | Not in release | Not in release |
pdftohtml | — | Not in release | Not in release | Not in release |
poppler | — | Fixed | Fixed | Fixed |
tetex-bin | — | Not in release | Not in release | Not in release |
texlive-bin | — | Not affected | Not affected | Not affected |
xpdf | — | Not affected | Not in release | Not affected |