Search CVE reports


Toggle filters

121 – 130 of 142 results


CVE-2007-0720

Medium priority
Ignored

The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection, which prevents other requests from being accepted.

1 affected package

cupsys

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cupsys
Show less packages

CVE-2006-1244

Medium priority

Some fixes available 4 of 5

Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vectors,...

6 affected packages

cupsys, gpdf, kdegraphics, koffice, poppler, tetex-bin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cupsys
gpdf
kdegraphics
koffice
poppler
tetex-bin
Show less packages

CVE-2005-4873

Medium priority
Not affected

Multiple stack-based buffer overflows in the phpcups PHP module for CUPS 1.1.23rc1 might allow context-dependent attackers to execute arbitrary code via vectors that result in long function parameters, as demonstrated by...

1 affected package

cupsys

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cupsys
Show less packages

CVE-2005-3627

Medium priority
Fixed

Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code via a DCTDecode stream with (1) a large...

6 affected packages

cupsys, gpdf, kdegraphics, koffice, poppler, tetex-bin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cupsys
gpdf
kdegraphics
koffice
poppler
tetex-bin
Show less packages

CVE-2005-3625

Medium priority
Fixed

Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1)...

6 affected packages

cupsys, gpdf, kdegraphics, koffice, poppler, tetex-bin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cupsys
gpdf
kdegraphics
koffice
poppler
tetex-bin
Show less packages

CVE-2005-3624

Medium priority
Fixed

The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode...

6 affected packages

cupsys, gpdf, kdegraphics, koffice, poppler, tetex-bin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cupsys
gpdf
kdegraphics
koffice
poppler
tetex-bin
Show less packages

CVE-2005-3192

Medium priority
Fixed

Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows...

6 affected packages

cupsys, gpdf, kdegraphics, koffice, poppler, tetex-bin

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cupsys
gpdf
kdegraphics
koffice
poppler
tetex-bin
Show less packages

CVE-2005-3191

Medium priority
Fixed

Multiple heap-based buffer overflows in the (1) DCTStream::readProgressiveSOF and (2) DCTStream::readBaselineSOF functions in the DCT stream parsing code (Stream.cc) in xpdf 3.01 and earlier, as used in products such as (a)...

9 affected packages

cupsys, gpdf, kdegraphics, koffice, libextractor...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cupsys
gpdf
kdegraphics
koffice
libextractor
pdftohtml
poppler
tetex-bin
xpdf
Show all 9 packages Show less packages

CVE-2005-3193

Medium priority
Fixed

Heap-based buffer overflow in the JPXStream::readCodestream function in the JPX stream parsing code (JPXStream.c) for xpdf 3.01 and earlier, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, (4) CUPS, and...

7 affected packages

cupsys, kdegraphics, koffice, pdftohtml, poppler...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cupsys
kdegraphics
koffice
pdftohtml
poppler
tetex-bin
xpdf
Show all 7 packages Show less packages

CVE-2005-2874

Medium priority
Not affected

The is_path_absolute function in scheduler/client.c for the daemon in CUPS before 1.1.23 allows remote attackers to cause a denial of service (CPU consumption by tight loop) via a "..\.." URL in an HTTP request.

1 affected package

cupsys

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cupsys
Show less packages