peter bassill · operator
$ cve CVE-2008-3641 JSON

CVE-2008-3641 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 24.1% (pctl 98)

Patch early

A public exploit exists.

Description

The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and pen color opcodes that overwrite arbitrary memory.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS24.13% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-399
On CISA KEVno
Public exploityes
Published2008-10-10
Last modified2026-06-16

Affected (1)

VendorProduct
applecups

Public exploits

SourceTitleDate
exploit-dbCUPS 1.3.7 - 'HP-GL/2' Filter Remote Code Execution2008-10-09

References

→ the Explorer  ·  watch your stack  ·  NVD