Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cups

First CVE: Dec 31, 2005Active for: 21 yearsTotal CVEs: 10
55.2
VTI Score
TOP TARGET

CUPS is a modestly represented printing service that serves as a standard component in many Unix and Linux distributions, placing it in a position of widespread deployment across servers and workstations despite its narrow product scope. Its vulnerabilities center on memory-safety and input-handling issues—including buffer-boundary violations, improper input validation, and cross-site scripting—characteristic of a network-facing daemon handling untrusted print-job data and configuration interfaces. Live severity, exploitation, and current exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Cups over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2005
20 years ago
Most Recent CVE
Aug 10, 2018
2,905 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2015-1158HIGH
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-host-name attributes, which allows remot
Jun 26, 201510.053NOYES
CVE-2008-0882HIGH
Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code
Feb 21, 200810.029NONO
CVE-2018-6553HIGH
The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possibly use this issue to escape confinement. This flaw affects v
Aug 10, 20188.828NONO
CVE-2008-0047HIGH
Heap-based buffer overflow in the cgiCompileSearch function in CUPS 1.3.5, and other versions including the version bundled with Apple Mac OS X 10.5.2, when printer sharing is enab
Mar 18, 20089.327NONO
CVE-2007-4351HIGH
Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted (1) textWithLanguage or (2) nameWi
Oct 31, 200710.027NONO
CVE-2014-8166HIGH
The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to execute arbitrary code via a craft
Jan 12, 20188.823NONO
CVE-2005-4873HIGH
Multiple stack-based buffer overflows in the phpcups PHP module for CUPS 1.1.23rc1 might allow context-dependent attackers to execute arbitrary code via vectors that result in long
Dec 31, 20057.520NONO
CVE-2007-0720MEDIUM
The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection, which prevents other request
Mar 13, 20075.018NONO
CVE-2015-1159MEDIUM
Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows remote attackers to inject arbitrary web
Jun 26, 20154.316NONO
CVE-2008-1722MEDIUM
Multiple integer overflows in (1) filter/image-png.c and (2) filter/image-zoom.c in CUPS 1.3 allow attackers to cause a denial of service (crash) and trigger memory corruption, as
Apr 10, 20084.316NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
30%
70%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (10.0%)
Network1 (10.0%)
Unknown8 (80.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (20.0%)
High0 (0.0%)
Unknown8 (80.0%)
User Interaction
None1 (10.0%)
Unknown8 (80.0%)
Required1 (10.0%)
Privileges Required
Low1 (10.0%)
High0 (0.0%)
None1 (10.0%)
Unknown8 (80.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
10.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cups.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cups — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cups's Products

View all 4 CNAs →

Top CWEs