Логотип exploitDog
bind:"CVE-2010-0540" OR bind:"CVE-2010-0542" OR bind:"CVE-2010-1748"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2010-0540" OR bind:"CVE-2010-0542" OR bind:"CVE-2010-1748"

Количество 16

Количество 16

oracle-oval логотип

ELSA-2010-0490

около 15 лет назад

ELSA-2010-0490: cups security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2010-0540

около 15 лет назад

Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.

CVSS2: 6
EPSS: Низкий
redhat логотип

CVE-2010-0540

около 15 лет назад

Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2010-0540

около 15 лет назад

Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.

CVSS2: 6
EPSS: Низкий
debian логотип

CVE-2010-0540

около 15 лет назад

Cross-site request forgery (CSRF) vulnerability in the web interface i ...

CVSS2: 6
EPSS: Низкий
github логотип

GHSA-hfwh-42mw-69v8

около 3 лет назад

Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.

EPSS: Низкий
ubuntu логотип

CVE-2010-1748

около 15 лет назад

The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2010-1748

около 15 лет назад

The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.

CVSS2: 3.3
EPSS: Средний
nvd логотип

CVE-2010-1748

около 15 лет назад

The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2010-1748

около 15 лет назад

The cgi_initialize_string function in cgi-bin/var.c in the web interfa ...

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2010-0542

около 15 лет назад

The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2010-0542

около 15 лет назад

The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2010-0542

около 15 лет назад

The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2010-0542

около 15 лет назад

The _WriteProlog function in texttops.c in texttops in the Text Filter ...

CVSS2: 6.8
EPSS: Низкий
github логотип

GHSA-vcrj-62jj-6wf5

около 3 лет назад

The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.

EPSS: Средний
github логотип

GHSA-cwfp-wwxr-hhq6

около 3 лет назад

The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2010-0490

ELSA-2010-0490: cups security update (IMPORTANT)

около 15 лет назад
ubuntu логотип
CVE-2010-0540

Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.

CVSS2: 6
0%
Низкий
около 15 лет назад
redhat логотип
CVE-2010-0540

Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.

CVSS2: 5.1
0%
Низкий
около 15 лет назад
nvd логотип
CVE-2010-0540

Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.

CVSS2: 6
0%
Низкий
около 15 лет назад
debian логотип
CVE-2010-0540

Cross-site request forgery (CSRF) vulnerability in the web interface i ...

CVSS2: 6
0%
Низкий
около 15 лет назад
github логотип
GHSA-hfwh-42mw-69v8

Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.

0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2010-1748

The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.

CVSS2: 4.3
13%
Средний
около 15 лет назад
redhat логотип
CVE-2010-1748

The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.

CVSS2: 3.3
13%
Средний
около 15 лет назад
nvd логотип
CVE-2010-1748

The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.

CVSS2: 4.3
13%
Средний
около 15 лет назад
debian логотип
CVE-2010-1748

The cgi_initialize_string function in cgi-bin/var.c in the web interfa ...

CVSS2: 4.3
13%
Средний
около 15 лет назад
ubuntu логотип
CVE-2010-0542

The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.

CVSS2: 6.8
4%
Низкий
около 15 лет назад
redhat логотип
CVE-2010-0542

The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.

CVSS2: 5.8
4%
Низкий
около 15 лет назад
nvd логотип
CVE-2010-0542

The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.

CVSS2: 6.8
4%
Низкий
около 15 лет назад
debian логотип
CVE-2010-0542

The _WriteProlog function in texttops.c in texttops in the Text Filter ...

CVSS2: 6.8
4%
Низкий
около 15 лет назад
github логотип
GHSA-vcrj-62jj-6wf5

The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.

13%
Средний
около 3 лет назад
github логотип
GHSA-cwfp-wwxr-hhq6

The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain calloc calls, which allows remote attackers to cause a denial of service (NULL pointer dereference or heap memory corruption) or possibly execute arbitrary code via a crafted file.

4%
Низкий
около 3 лет назад

Уязвимостей на страницу