Cups
Vendor:
First CVE: Dec 26, 2002 · Active for 23 years
56
Total CVEs
More Total CVEs than 98% of tracked products
4.3
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cups over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 26, 2002
23 years ago
Most Recent CVE
May 26, 2022
1,521 days ago
CVE Severity & Scoring
Cups56 CVEs
11%
59%
25%
All CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (1.8%)
Network11 (19.6%)
Unknown44 (78.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (17.9%)
High2 (3.6%)
Unknown44 (78.6%)
User Interaction
None12 (21.4%)
Unknown44 (78.6%)
Required0 (0.0%)
Privileges Required
Low1 (1.8%)
High1 (1.8%)
None10 (17.9%)
Unknown44 (78.6%)
Top CVEs
Signals from CVEs in this product scope (56 CVEs).
56 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-3641HIGH The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and pen color opcodes that overwrit | Oct 10, 2008 | 10.0 | 47 | NO | YES |
CVE-2009-0949HIGH The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of | Jun 9, 2009 | 7.5 | 38 | NO | YES |
CVE-2012-5519HIGH CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, whi | Nov 20, 2012 | 7.2 | 36 | NO | YES |
CVE-2008-5183HIGH cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which | Nov 21, 2008 | 7.5 | 34 | NO | YES |
CVE-2010-2941CRITICAL ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of s | Nov 5, 2010 | 9.8 | 33 | NO | NO |
CVE-2012-6094CRITICAL cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system | Dec 20, 2019 | 9.8 | 30 | NO | NO |
CVE-2010-1748MEDIUM The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, d | Jun 17, 2010 | 4.3 | 30 | NO | YES |
CVE-2004-2154CRITICAL CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows attackers to bypass intended ACLs via a printer name containing uppercase or lowerca | Dec 31, 2004 | 9.8 | 30 | NO | NO |
CVE-2008-0053HIGH Multiple buffer overflows in the HP-GL/2-to-PostScript filter in CUPS before 1.3.6 might allow remote attackers to execute arbitrary code via a crafted HP-GL/2 file. | Mar 18, 2008 | 10.0 | 28 | NO | NO |
CVE-2010-3702HIGH The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows con | Nov 5, 2010 | 7.5 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (56 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.8% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
8.9% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (56 CVEs).
Media Mentions
Signals from CVEs in this product scope (56 CVEs).
Top CNAs Publishing CVEs For Cups
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.7.4 | 1 | 1.5 | 0.3% | 0 | 0 |
| 1.7.3 | 2 | 3.5 | 1.6% | 0 | 0 |
| 1.7.2 | 3 | 2.7 | 1.2% | 0 | 0 |
| 1.7.1 | 5 | 2.7 | 1.2% | 0 | 0 |
| 1.7.0 | 4 | 3.1 | 1.3% | 0 | 0 |
| 1.7 | 5 | 2.7 | 1.1% | 0 | 0 |
| 1.6.4 | 1 | 4.3 | 1.6% | 0 | 0 |
| 1.6.3 | 1 | 4.3 | 1.6% | 0 | 0 |
| 1.6.2 | 1 | 4.3 | 1.6% | 0 | 0 |
| 1.6.1 | 1 | 4.3 | 1.6% | 0 | 0 |
| 1.6 | 1 | 4.3 | 1.6% | 0 | 0 |
| 1.5.4 | 1 | 4.3 | 1.6% | 0 | 0 |
| 1.5.3 | 1 | 4.3 | 1.6% | 0 | 0 |
| 1.5.2 | 1 | 4.3 | 1.6% | 0 | 0 |
| 1.5.1 | 1 | 4.3 | 1.6% | 0 | 0 |
| 1.5.0 | 1 | 4.3 | 1.6% | 0 | 0 |
| 1.5 | 1 | 4.3 | 1.6% | 0 | 0 |
| 1.4.8 | 1 | 4.3 | 1.6% | 0 | 0 |
| 1.4.7 | 2 | 4.7 | 2.8% | 0 | 0 |
| 1.4.6 | 2 | 4.7 | 2.8% | 0 | 0 |