Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 25

Количество 25

suse-cvrf логотип

SUSE-SU-2015:0575-1

около 12 лет назад

Security update for CUPS

EPSS: Низкий
github логотип

GHSA-pmc2-2vx8-fmwf

около 4 лет назад

Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter to help/.

EPSS: Низкий
github логотип

GHSA-f3f2-vc32-jrrx

около 4 лет назад

The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-host-name attributes, which allows remote attackers to trigger data corruption for reference-counted strings via a crafted (1) IPP_CREATE_JOB or (2) IPP_PRINT_JOB request, as demonstrated by replacing the configuration file and consequently executing arbitrary code.

EPSS: Средний
fstec логотип

BDU:2015-10516

около 11 лет назад

Уязвимость функции cgi_puts сервера печати CUPS, позволяющая нарушителю внедрить произвольный JavaScript- или HTML-код в формируемые страницы веб-интерфейса

CVSS2: 4.3
EPSS: Низкий
fstec логотип

BDU:2015-10444

около 11 лет назад

Уязвимость сервера печати CUPS, позволяющая нарушителю изменить файл конфигурации устройства или выполнить произвольный код

CVSS2: 10
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
suse-cvrf логотип
SUSE-SU-2015:0575-1

Security update for CUPS

около 12 лет назад
github логотип
GHSA-pmc2-2vx8-fmwf

Cross-site scripting (XSS) vulnerability in the cgi_puts function in cgi-bin/template.c in the template engine in CUPS before 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter to help/.

7%
Низкий
около 4 лет назад
github логотип
GHSA-f3f2-vc32-jrrx

The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-host-name attributes, which allows remote attackers to trigger data corruption for reference-counted strings via a crafted (1) IPP_CREATE_JOB or (2) IPP_PRINT_JOB request, as demonstrated by replacing the configuration file and consequently executing arbitrary code.

30%
Средний
около 4 лет назад
fstec логотип
BDU:2015-10516

Уязвимость функции cgi_puts сервера печати CUPS, позволяющая нарушителю внедрить произвольный JavaScript- или HTML-код в формируемые страницы веб-интерфейса

CVSS2: 4.3
7%
Низкий
около 11 лет назад
fstec логотип
BDU:2015-10444

Уязвимость сервера печати CUPS, позволяющая нарушителю изменить файл конфигурации устройства или выполнить произвольный код

CVSS2: 10
30%
Средний
около 11 лет назад

Уязвимостей на страницу