Known vulnerabilities in cups (Alpine package)

Software CPE: cpe:2.3:o:alpine:cups_alpine_package:*:*:*:*:*:alpine_linux:*:*
Total vulnerabilities: 15
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting cups (Alpine package) cups (Alpine package) is affected by 15 known vulnerabilities: 3 high, 4 medium, 8 low Critical High Medium Low

Vulnerabilities (15)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU27378 - Out-of-bounds read
CVE-2019-8842
CWE-125 Low
No
No
- 28.04.2020 SB2020042708
SB2020061073
SB2022053129
and 2 more
#VU27341 - Heap-based Buffer Overflow
CVE-2020-3898
CWE-122 Medium
No
No
- 27.04.2020 SB2020042707
SB2020042708
SB2020042819
and 7 more
#VU23042 - Stack-based buffer overflow
CVE-2019-8675
CWE-121 High
No
No
2.2.12-r0 27.11.2019 SB2019112715
SB2019112716
SB2019081611
and 8 more
#VU23040 - Stack-based buffer overflow
CVE-2019-8696
CWE-121 High
No
No
2.2.12-r0 27.11.2019 SB2019112715
SB2019112716
SB2019081611
and 8 more
#VU16519 - Cross-Site Request Forgery (CSRF)
CVE-2018-4700
CWE-352 Low
No
No
2.2.10-r0 13.12.2018 SB2018121305
SB2018121709
SB2020040121
and 7 more
#VU10942 - Command injection
CVE-2017-18190
CWE-77 Low
No
No
2.1.3-r2 12.03.2018 SB2018022016
SB2018030712
SB2018030504
and 3 more
#VU32417 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2015-1159
CWE-79 Low
No
No
1.7.4-r2 26.06.2015 SB2015062603
SB2015061521
SB2015061105
and 4 more
#VU32416 - Security Features
CVE-2015-1158
CWE-254 High
Available
No
1.7.4-r2 26.06.2015 SB2015062602
SB2015061520
SB2015061105
and 5 more
#VU32436 - Memory corruption
CVE-2014-9679
CWE-119 Medium
No
No
1.6.2-r4 19.02.2015 SB2015021903
SB2015031807
SB2015070723
and 2 more
#VU33296 - Improper Link Resolution Before File Access ('Link Following')
CVE-2014-5029
CWE-59 Low
No
No
1.6.2-r1 29.07.2014 SB2014072903
SB2014071504
#VU32504 - Improper Link Resolution Before File Access ('Link Following')
CVE-2014-3537
CWE-59 Low
No
No
1.6.2-r1 23.07.2014 SB2014072301
SB2014082101
#VU32526 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2014-2856
CWE-79 Low
No
No
1.6.1-r1 18.04.2014 SB2014041802
SB2014052804
#VU32580 - Improper Link Resolution Before File Access ('Link Following')
CVE-2013-6891
CWE-59 Low
No
No
1.7.1-r0 26.01.2014 SB2014012601
SB2014020522
#VU33331 - Heap-based Buffer Overflow
CVE-2011-3170
CWE-122 Medium
No
No
1.4.8-r0 19.08.2011 SB2011081903
SB2011120203
#VU32839 - Heap-based Buffer Overflow
CVE-2011-2896
CWE-122 Medium
No
No
1.4.8-r0 19.08.2011 SB2011081901
SB2011111006
SB2011111007