Easy Software Products maintains CUPS (Common Unix Printing System), a widely embedded print-management daemon that operates across Unix and Linux distributions, enterprise servers, and numerous downstream appliances despite a minimal direct product footprint. The vendor's vulnerability footprint, though modest in volume, sits deep in the software supply chain; CUPS's role as a foundational printing service means that individual flaws propagate across a vast landscape of dependent systems and distributions. Vulnerabilities affecting this vendor frequently acquire public exploit code, consistent with CUPS's accessibility and appeal as a hardening target for systems administrators. The recurring weakness classes include memory-buffer-boundary issues and input-validation defects that reflect the parsing and privilege-separation demands of a daemon handling untrusted print jobs and network protocols. Defenders should track CUPS advisories closely and prioritize patching across server and embedded-device inventory, since remediation often depends on distribution or downstream vendor updates rather than direct patches from this vendor; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Easy Software Products over time
Signals from CVEs in this vendor scope (35 CVEs).
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-5849HIGH Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute arbitrary code via a crafted S | Dec 19, 2007 | 9.3 | 39 | NO | YES |
CVE-2004-0558MEDIUM The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of service (service hang) via a certain UDP packet to the IPP po | Sep 28, 2004 | 5.0 | 36 | NO | YES |
CVE-2002-1368HIGH Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative argume | Dec 26, 2002 | 7.5 | 35 | NO | YES |
CVE-2004-0888HIGH Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (cras | Jan 27, 2005 | 10.0 | 34 | NO | NO |
CVE-2004-1267MEDIUM Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops program for CUPS 1.1.22 allows remote attackers to execute arbitrary code via a crafted HPGL file. | Jan 10, 2005 | 6.5 | 34 | NO | YES |
CVE-2002-1383HIGH Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonst | Dec 26, 2002 | 10.0 | 34 | NO | NO |
CVE-2004-0889HIGH Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitra | Jan 27, 2005 | 10.0 | 33 | NO | NO |
CVE-2004-0926HIGH Heap-based buffer overflow in Apple QuickTime on Mac OS 10.2.8 through 10.3.5 may allow remote attackers to execute arbitrary code via a certain BMP image. | Jan 27, 2005 | 10.0 | 32 | NO | NO |
CVE-2004-1125HIGH Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows | Jan 10, 2005 | 9.3 | 31 | NO | NO |
CVE-2004-1269MEDIUM lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subsequent invocations of lppasswd | Jan 10, 2005 | 5.0 | 31 | NO | YES |
Signals from CVEs in this vendor scope (35 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Easy Software Products.
Media articles that mention a CVE ID that affects a product developed by Easy Software Products — matched by CVE ID, not by vendor name.