Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Easy Software Products

First CVE: May 3, 2001Active for: 25 yearsTotal CVEs: 35
50.1
VTI Score
TOP TARGET

Easy Software Products maintains CUPS (Common Unix Printing System), a widely embedded print-management daemon that operates across Unix and Linux distributions, enterprise servers, and numerous downstream appliances despite a minimal direct product footprint. The vendor's vulnerability footprint, though modest in volume, sits deep in the software supply chain; CUPS's role as a foundational printing service means that individual flaws propagate across a vast landscape of dependent systems and distributions. Vulnerabilities affecting this vendor frequently acquire public exploit code, consistent with CUPS's accessibility and appeal as a hardening target for systems administrators. The recurring weakness classes include memory-buffer-boundary issues and input-validation defects that reflect the parsing and privilege-separation demands of a daemon handling untrusted print jobs and network protocols. Defenders should track CUPS advisories closely and prioritize patching across server and embedded-device inventory, since remediation often depends on distribution or downstream vendor updates rather than direct patches from this vendor; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
35
Total CVEs
More Total CVEs than 98% of tracked vendors
5.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Easy Software Products over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 3, 2001
25 years ago
Most Recent CVE
Apr 4, 2008
6,685 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (35 CVEs).

35 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2007-5849HIGH
Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute arbitrary code via a crafted S
Dec 19, 20079.339NOYES
CVE-2004-0558MEDIUM
The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of service (service hang) via a certain UDP packet to the IPP po
Sep 28, 20045.036NOYES
CVE-2002-1368HIGH
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative argume
Dec 26, 20027.535NOYES
CVE-2004-0888HIGH
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (cras
Jan 27, 200510.034NONO
CVE-2004-1267MEDIUM
Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops program for CUPS 1.1.22 allows remote attackers to execute arbitrary code via a crafted HPGL file.
Jan 10, 20056.534NOYES
CVE-2002-1383HIGH
Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonst
Dec 26, 200210.034NONO
CVE-2004-0889HIGH
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitra
Jan 27, 200510.033NONO
CVE-2004-0926HIGH
Heap-based buffer overflow in Apple QuickTime on Mac OS 10.2.8 through 10.3.5 may allow remote attackers to execute arbitrary code via a certain BMP image.
Jan 27, 200510.032NONO
CVE-2004-1125HIGH
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows
Jan 10, 20059.331NONO
CVE-2004-1269MEDIUM
lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subsequent invocations of lppasswd
Jan 10, 20055.031NOYES
View all 35 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products35 CVEs
11%
43%
46%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown35 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown35 (100.0%)
User Interaction
None0 (0.0%)
Unknown35 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown35 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (35 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
14.3% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Easy Software Products.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Easy Software Products — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Easy Software Products's Products

View all 2 CNAs →

Top CWEs