Логотип exploitDog
bind:"CVE-2010-0540" OR bind:"CVE-2010-0542" OR bind:"CVE-2010-1748"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2010-0540" OR bind:"CVE-2010-0542" OR bind:"CVE-2010-1748"

Количество 16

Количество 16

oracle-oval логотип

ELSA-2010-0490

больше 15 лет назад

ELSA-2010-0490: cups security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2010-0540

больше 15 лет назад

Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.

CVSS2: 6
EPSS: Низкий
redhat логотип

CVE-2010-0540

больше 15 лет назад

Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2010-0540

больше 15 лет назад

Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.

CVSS2: 6
EPSS: Низкий
debian логотип

CVE-2010-0540

больше 15 лет назад

Cross-site request forgery (CSRF) vulnerability in the web interface i ...

CVSS2: 6
EPSS: Низкий
github логотип

GHSA-hfwh-42mw-69v8

больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.

EPSS: Низкий
ubuntu логотип

CVE-2010-1748

больше 15 лет назад

The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2010-1748

больше 15 лет назад

The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.

CVSS2: 3.3
EPSS: Средний
nvd логотип

CVE-2010-1748

больше 15 лет назад

The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2010-1748

больше 15 лет назад

The cgi_initialize_string function in cgi-bin/var.c in the web interfa ...

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2010-0542

больше 15 лет назад

The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2010-0542

больше 15 лет назад

The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2010-0542

больше 15 лет назад

The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2010-0542

больше 15 лет назад

The _WriteProlog function in texttops.c in texttops in the Text Filter ...

CVSS2: 6.8
EPSS: Низкий
github логотип

GHSA-vcrj-62jj-6wf5

больше 3 лет назад

The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.

EPSS: Средний
github логотип

GHSA-cwfp-wwxr-hhq6

больше 3 лет назад

The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2010-0490

ELSA-2010-0490: cups security update (IMPORTANT)

больше 15 лет назад
ubuntu логотип
CVE-2010-0540

Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.

CVSS2: 6
0%
Низкий
больше 15 лет назад
redhat логотип
CVE-2010-0540

Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.

CVSS2: 5.1
0%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-0540

Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.

CVSS2: 6
0%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-0540

Cross-site request forgery (CSRF) vulnerability in the web interface i ...

CVSS2: 6
0%
Низкий
больше 15 лет назад
github логотип
GHSA-hfwh-42mw-69v8

Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.

0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2010-1748

The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.

CVSS2: 4.3
13%
Средний
больше 15 лет назад
redhat логотип
CVE-2010-1748

The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.

CVSS2: 3.3
13%
Средний
больше 15 лет назад
nvd логотип
CVE-2010-1748

The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.

CVSS2: 4.3
13%
Средний
больше 15 лет назад
debian логотип
CVE-2010-1748

The cgi_initialize_string function in cgi-bin/var.c in the web interfa ...

CVSS2: 4.3
13%
Средний
больше 15 лет назад
ubuntu логотип
CVE-2010-0542

The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.

CVSS2: 6.8
4%
Низкий
больше 15 лет назад
redhat логотип
CVE-2010-0542

The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.

CVSS2: 5.8
4%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-0542

The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.

CVSS2: 6.8
4%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-0542

The _WriteProlog function in texttops.c in texttops in the Text Filter ...

CVSS2: 6.8
4%
Низкий
больше 15 лет назад
github логотип
GHSA-vcrj-62jj-6wf5

The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.

13%
Средний
больше 3 лет назад
github логотип
GHSA-cwfp-wwxr-hhq6

The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.

4%
Низкий
больше 3 лет назад

Уязвимостей на страницу