Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

cups — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in cups, with AI-generated Chinese analysis, references, and POCs.

Vendor: cups

CVE IDTitleCVSSSeverityPublished
CVE-2026-41079 OpenPrinting CUPS: Heap out-of-bounds read in SNMP supply-level polling leaks stack memory to authenticated users CWE-125 4.3 Medium2026-04-24
CVE-2026-39316 CUPS has a use-after-free in `cupsdDeleteTemporaryPrinters` via dangling subscription pointer CWE-416 4.0 Medium2026-04-07
CVE-2026-39314 CUPS has an integer underflow in `_ppdCreateFromIPP` causes root cupsd crash via negative `job-password-supported` CWE-191 4.0 Medium2026-04-07
CVE-2026-34980 OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network CWE-20 9.8AICriticalAI2026-04-03
CVE-2026-34979 OpenPrinting CUPS: Heap overflow in `get_options()` CWE-122 5.3 Medium2026-04-03
CVE-2026-34978 OpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of job.cache) CWE-22 6.5 Medium2026-04-03
CVE-2026-34990 OpenPrinting CUPS: Local print admin token disclosure using temporary printers CWE-287 7.8AIHighAI2026-04-03
CVE-2026-27447 OpenPrinting CUPS: Authorization bypass via case-insensitive group-member lookup CWE-863 4.8 Medium2026-04-03
CVE-2025-58436 OpenPrinting CUPS slow client can halt cupsd, leading to a possible DoS attack CWE-400 5.1 Medium2025-11-29
CVE-2025-61915 OpenPrinting CUPS vulnerable to stack based out-of-bound write CWE-129 6.0 Medium2025-11-29
CVE-2025-58364 cups: Remote DoS via null dereference CWE-20 6.5 Medium2025-09-11
CVE-2025-58060 cups has Authentication bypass with AuthType Negotiate CWE-287 8.0 High2025-09-11
CVE-2024-35235 Cupsd Listen arbitrary chmod 0140777 CWE-59 4.4 Medium2024-06-11
CVE-2023-4504 OpenPrinting CUPS/libppd Postscript Parsing Heap Overflow CWE-122 7.8 -2023-09-21
CVE-2023-34241 CUPS vulnerable to use-after-free in cupsdAcceptClient() CWE-416 5.3 Medium2023-06-22
CVE-2023-32324 OpenPrinting CUPS vulnerable to heap buffer overflow CWE-122 7.5 High2023-06-01
CVE-2012-6094 Apple CUPS 安全漏洞 8.4 -2019-12-20
CVE-2018-4300 CPUS 信息泄露漏洞 5.9 -2019-04-03
CVE-2018-6553 AppArmor cupsd Sandbox Bypass Due to Use of Hard Links 8.8 -2018-08-10

All 19 known CVE vulnerabilities affecting cups with full Chinese analysis, references, and POCs where available.