CUPS is a modestly represented printing service that serves as a standard component in many Unix and Linux distributions, placing it in a position of widespread deployment across servers and workstations despite its narrow product scope. Its vulnerabilities center on memory-safety and input-handling issues—including buffer-boundary violations, improper input validation, and cross-site scripting—characteristic of a network-facing daemon handling untrusted print-job data and configuration interfaces. Live severity, exploitation, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cups over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-1158HIGH The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-host-name attributes, which allows remot | Jun 26, 2015 | 10.0 | 53 | NO | YES |
CVE-2008-0882HIGH Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code | Feb 21, 2008 | 10.0 | 29 | NO | NO |
CVE-2018-6553HIGH The CUPS AppArmor profile incorrectly confined the dnssd backend due to use of hard links. A local attacker could possibly use this issue to escape confinement. This flaw affects v | Aug 10, 2018 | 8.8 | 28 | NO | NO |
CVE-2008-0047HIGH Heap-based buffer overflow in the cgiCompileSearch function in CUPS 1.3.5, and other versions including the version bundled with Apple Mac OS X 10.5.2, when printer sharing is enab | Mar 18, 2008 | 9.3 | 27 | NO | NO |
CVE-2007-4351HIGH Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted (1) textWithLanguage or (2) nameWi | Oct 31, 2007 | 10.0 | 27 | NO | NO |
CVE-2014-8166HIGH The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to execute arbitrary code via a craft | Jan 12, 2018 | 8.8 | 23 | NO | NO |
CVE-2005-4873HIGH Multiple stack-based buffer overflows in the phpcups PHP module for CUPS 1.1.23rc1 might allow context-dependent attackers to execute arbitrary code via vectors that result in long | Dec 31, 2005 | 7.5 | 20 | NO | NO |
CVE-2007-0720MEDIUM The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection, which prevents other request | Mar 13, 2007 | 5.0 | 18 | NO | NO |
CVE-2015-1159MEDIUM Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows remote attackers to inject arbitrary web | Jun 26, 2015 | 4.3 | 16 | NO | NO |
CVE-2008-1722MEDIUM Multiple integer overflows in (1) filter/image-png.c and (2) filter/image-zoom.c in CUPS 1.3 allow attackers to cause a denial of service (crash) and trigger memory corruption, as | Apr 10, 2008 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cups.
Media articles that mention a CVE ID that affects a product developed by Cups — matched by CVE ID, not by vendor name.