Known vulnerabilities in cups (Red Hat package)
Vendor:
Red Hat Inc.
Software:
cups (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:cups_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
20
Public exploits:
2
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
2.2.6-68.el8_10
2.2.6-66.el8_10
2.4.10-12.el10_1.2
2.2.6-64.el8_10
2.2.6-33.el8_2.3
2.2.6-45.el8_6.6
2.2.6-38.el8_4.3
1.6.3-52.el7_9.1
2.2.6-51.el8_8.5
2.3.3op2-27.el9_4.1
2.3.3op2-16.el9_2.4
2.3.3op2-13.el9_0.4
2.2.6-63.el8_10
2.2.6-62.el8_10
2.3.3op2-31.el9_5
2.2.6-51.el8_8.4
2.2.6-45.el8_6.5
1.4.2-67.el6_6.1
1.6.3-17.el7
1.3.7-30.el5_9.3
1.4.2-50.el6_4.4
1.4.2-35.el6_0.1
1.3.7-18.el5_5.8
1.1.22-0.rc1.9.32.el4_8.10
1.1.22-0.rc1.9.32.el4_8.6
1.3.7-18.el5_5.4
1.3.7-11.el5_4.6
1.3.7-11.el5_4.4
1.1.22-0.rc1.9.32.el4_8.3
1.3.7-8.el5_3.6
1.1.22-0.rc1.9.27.el4_7.5
1.3.7-8.el5_3.4
1.2.4-11.18.el5_2.3
1.1.22-0.rc1.9.27.el4_7.1
1.2.4-11.18.el5_2.2
1.1.22-0.rc1.9.20.2.el4_6.8
1.2.4-11.18.el5_2.1
1.1.22-0.rc1.9.20.2.el4_6.6
1.2.4-11.14.el5_1.6
1.1.22-0.rc1.9.20.2.el4_6.5
1.2.4-11.14.el5_1.4
1.1.22-0.rc1.9.20.2.el4_5.2
1.2.4-11.14.el5_1.3
1.2.4-11.14.el5_1.1
2.2.6-51.el8_8.3
2.2.6-45.el8_6.4
2.2.6-54.el8_9
2.3.3op2-21.el9
2.2.6-51.el8_8.1
2.3.3op2-16.el9_2.1
2.2.6-28.el8_1.2
1.6.3-52.el7_9
2.2.6-38.el8_4.2
2.3.3op2-13.el9_0.2
2.2.6-45.el8_6.3
2.2.6-33.el8_2.2
filters/1.20.0/19.el8_2.1/fd431d51/cups-filters-1.20.0-19.el8_2.1
2.2.6-40.el8
2.3.3op2-13.el9_0.1
2.2.6-28.el8_1.1
2.2.6-33.el8_2.1
2.2.6-45.el8_6.2
2.2.6-38.el8_4.1
2.2.6-38.el8
1.6.3-51.el7
2.2.6-33.el8
1.6.3-43.el7
1.2.4-11.5.1.el5
1.2.4-11.5.3.el5
1.3.7-30.el5
1.4.2-81.el6_10
1.4.2-80.el6_10
1.4.2-79.el6
1.4.2-78.el6_9
1.4.2-77.el6
1.4.2-74.el6
1.4.2-72.el6
1.4.2-67.el6_6
1.4.2-67.el6
1.4.2-52.el6_5
1.4.2-50.el6_4
1.4.2-48.el6_3
1.4.2-48.el6
1.4.2-44.el6_2
1.4.2-44.el6
1.4.2-39.el6_1
1.4.2-39.el6
1.4.2-35.el6_0
1.4.2-35.el6
Vulnerabilities (20)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU124813 - Improper input validation CVE-2026-34980 |
CWE-20 | High | 2.2.6-68.el8_10 | 02.04.2026 |
SB2026040206 SB20260417145 SB20260417146 and 11 more |
||
| #VU118818 - Resource exhaustion CVE-2025-58436 |
CWE-400 | Low | 2.2.6-66.el8_10, 2.4.10-12.el10_1.2 | 27.11.2025 |
SB2025112765 SB2025112856 SB2025120406 and 16 more |
||
| #VU118817 - Out-of-bounds write CVE-2025-61915 |
CWE-787 | Low | 2.2.6-66.el8_10, 2.4.10-12.el10_1.2 | 27.11.2025 |
SB2025112765 SB2025112772 SB2025112855 and 14 more |
||
| #VU115165 - NULL Pointer Dereference CVE-2025-58364 |
CWE-476 | Medium | 2.2.6-64.el8_10, 2.3.3op2-13.el9_0.4, 2.3.3op2-16.el9_2.4, 2.3.3op2-27.el9_4.1 | 11.09.2025 |
SB2025091140 SB2025091147 SB2025091148 and 18 more |
||
| #VU115164 - Improper Authentication CVE-2025-58060 |
CWE-287 | High | 1.6.3-52.el7_9.1, 2.2.6-33.el8_2.3, 2.2.6-38.el8_4.3, 2.2.6-45.el8_6.6, 2.2.6-51.el8_8.5, 2.2.6-63.el8_10, 2.3.3op2-13.el9_0.4, 2.3.3op2-16.el9_2.4, 2.3.3op2-27.el9_4.1 | 11.09.2025 |
SB2025091139 SB2025091141 SB2025091147 and 28 more |
||
| #VU97745 - Improper input validation CVE-2024-47175 |
CWE-20 | High | 2.2.6-62.el8_10, 2.3.3op2-31.el9_5 | 27.09.2024 |
SB2024092719 SB2024092722 SB2024092723 and 50 more |
||
| #VU92075 - UNIX Symbolic Link (Symlink) Following CVE-2024-35235 |
CWE-61 | Low | 2.2.6-45.el8_6.5, 2.2.6-51.el8_8.4 | 13.06.2024 |
SB2024061389 SB2024061398 SB2024061399 and 29 more |
||
| #VU77641 - Use After Free CVE-2023-34241 |
CWE-416 | Medium | 2.2.6-45.el8_6.4, 2.2.6-51.el8_8.3, 2.2.6-54.el8_9, 2.3.3op2-21.el9 | 22.06.2023 |
SB2023062261 SB2023062272 SB2023062276 and 36 more |
||
| #VU76761 - Heap-based Buffer Overflow CVE-2023-32324 |
CWE-122 | Medium | 2.2.6-45.el8_6.4, 2.2.6-51.el8_8.3, 2.2.6-54.el8_9, 2.3.3op2-21.el9 | 01.06.2023 |
SB2023060132 SB2023060133 SB2023060136 and 33 more |
||
| #VU76383 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2023-24805 |
CWE-78 | Medium | filters/1.20.0/19.el8_2.1/fd431d51/cups-filters-1.20.0-19.el8_2.1 | 19.05.2023 |
SB2023051940 SB2023051946 SB2023051947 and 20 more |
||
| #VU76308 - Improper Authentication CVE-2023-32360 |
CWE-287 | Medium | 1.6.3-52.el7_9, 2.2.6-28.el8_1.2, 2.2.6-33.el8_2.2, 2.2.6-38.el8_4.2, 2.2.6-45.el8_6.3, 2.2.6-51.el8_8.1, 2.3.3op2-13.el9_0.2, 2.3.3op2-16.el9_2.1 | 18.05.2023 |
SB2023051860 SB2023051901 SB2023051902 and 36 more |
||
| #VU63747 - Improper Authorization CVE-2022-26691 |
CWE-285 | High | 2.2.6-28.el8_1.1, 2.2.6-33.el8_2.1, 2.2.6-38.el8_4.1, 2.2.6-45.el8_6.2, 2.3.3op2-13.el9_0.1 | 26.05.2022 |
SB2022052625 SB2022052626 SB2022053018 and 30 more |
||
| #VU50402 - Out-of-bounds read CVE-2020-10001 |
CWE-125 | Medium | 2.2.6-40.el8 | 07.02.2021 |
SB2021020702 SB2021020703 SB2020121515 and 10 more |
||
| #VU27341 - Heap-based Buffer Overflow CVE-2020-3898 |
CWE-122 | Medium | 2.2.6-38.el8 | 27.04.2020 |
SB2020042707 SB2020042708 SB2020042819 and 7 more |
||
| #VU23042 - Stack-based buffer overflow CVE-2019-8675 |
CWE-121 | High | 1.6.3-51.el7, 2.2.6-33.el8 | 27.11.2019 |
SB2019112715 SB2019112716 SB2019081611 and 8 more |
||
| #VU23040 - Stack-based buffer overflow CVE-2019-8696 |
CWE-121 | High | 1.6.3-51.el7, 2.2.6-33.el8 | 27.11.2019 |
SB2019112715 SB2019112716 SB2019081611 and 8 more |
||
| #VU16519 - Cross-Site Request Forgery (CSRF) CVE-2018-4700 |
CWE-352 | Low | 1.6.3-43.el7 | 13.12.2018 |
SB2018121305 SB2018121709 SB2020040121 and 7 more |
||
| #VU13882 - Exposure of sensitive information to an unauthorized actor CVE-2018-4181 |
CWE-200 | Low | 1.6.3-43.el7 | 16.07.2018 |
SB2018071120 SB2018080804 SB2018081008 and 5 more |
||
| #VU13881 - Permissions, Privileges, and Access Controls CVE-2018-4180 |
CWE-264 | Low | 1.6.3-43.el7 | 16.07.2018 |
SB2018071120 SB2018080804 SB2018081008 and 5 more |
||
| #VU10942 - Command injection CVE-2017-18190 |
CWE-77 | Low | 1.6.3-51.el7 | 12.03.2018 |
SB2018022016 SB2018030712 SB2018030504 and 3 more |