Known Vulnerabilities for Cups by Apple
Listed below are 10 of the newest known vulnerabilities associated with "Cups" by "Apple".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2018-4300 | The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to t... | 5.9 - MEDIUM | 2019-04-03 | 2019-09-28 |
| CVE-2017-18248 | The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attacke... | 5.3 - MEDIUM | 2018-03-26 | 2018-07-13 |
| CVE-2017-18190 | A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to... | 7.5 - HIGH | 2018-02-16 | 2019-10-03 |
| CVE-2014-9679 | Integer underflow in the cupsRasterReadPixels function in filter/raster.c in CUPS before 2.0.2 allows remote attackers to hav... | 6.8 - MEDIUM | 2015-02-19 | 2018-10-30 |
| CVE-2014-5031 | The web interface in CUPS before 2.0 does not check that files have world-readable permissions, which allows remote attackers... | 5 - MEDIUM | 2014-07-29 | 2017-01-07 |
| CVE-2014-5030 | CUPS before 2.0 allows local users to read arbitrary files via a symlink attack on (1) index.html, (2) index.class, (3) index... | 1.9 - LOW | 2014-07-29 | 2017-01-07 |
| CVE-2014-5029 | The web interface in CUPS 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in ... | 1.5 - LOW | 2014-07-29 | 2017-01-07 |
| CVE-2014-3537 | The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a f... | 1.2 - LOW | 2014-07-23 | 2023-02-13 |
| CVE-2014-2856 | Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remo... | 4.3 - MEDIUM | 2014-04-18 | 2017-12-16 |
| CVE-2013-6891 | lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files vi... | 1.2 - LOW | 2014-01-26 | 2014-03-06 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apple | Cups | 2.2.9 | All | All | All |
| Application | Apple | Cups | 2.2.8 | All | All | All |
| Application | Apple | Cups | 2.2.7 | All | All | All |
| Application | Apple | Cups | 2.2.6 | All | All | All |
| Application | Apple | Cups | 2.2.5 | All | All | All |
| Application | Apple | Cups | 2.2.4 | All | All | All |
| Application | Apple | Cups | 2.2.3 | All | All | All |
| Application | Apple | Cups | 2.2.2 | All | All | All |
| Application | Apple | Cups | 2.2.10 | All | All | All |
| Application | Apple | Cups | 2.2.1 | All | All | All |
| Application | Apple | Cups | 2.2.0 | All | All | All |
| Application | Apple | Cups | 2.1.4 | All | All | All |
| Application | Apple | Cups | 2.1.3 | All | All | All |
| Application | Apple | Cups | 2.1.2 | All | All | All |
| Application | Apple | Cups | 2.1.0 | All | All | All |
| Application | Apple | Cups | 2.1 | All | All | All |
| Application | Apple | Cups | 2.0.4 | All | All | All |
| Application | Apple | Cups | 2.0.3 | All | All | All |
| Application | Apple | Cups | 2.0.2 | All | All | All |
| Application | Apple | Cups | 2.0.1 | All | All | All |