📦

cups-filters

Vendor: linuxfoundation

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 6 Remote Access
Total CVEs 38 Total Indexed
Avg. EPSS 9.05% Exploit Prob.
Latest CVE CVE-2025-64524 Nov 20

Security Vulnerability Index

Page 2 / 4
4.3 CVSS

The process_browse_data function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted packet data.

EPSS: 2.13%
5.8 CVSS

The generate_local_queue function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the host name. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707.

EPSS: 0.52%
8.3 CVSS

cups-browsed in cups-filters 1.0.41 before 1.0.51 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the (1) model or (2) PDL, related to "System V interface scripts generated for queues."

EPSS: 1.34%
4.4 CVSS

The OPVPWrapper::loadDriver function in oprs/OPVPWrapper.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows local users to gain privileges via a Trojan horse driver in the same directory as the PDF file.

EPSS: 0.30%
6.8 CVSS

Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, which triggers a heap-based buffer overflow.

EPSS: 14.11%
6.8 CVSS

Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows remote attackers to execute arbitrary code via a crafted PDF file.

EPSS: 14.18%
6.8 CVSS

Multiple heap-based buffer overflows in the urftopdf filter in cups-filters 1.0.25 before 1.0.47 allow remote attackers to execute arbitrary code via a large (1) page or (2) line in a URF file.

EPSS: 13.72%