peter bassill · operator
$ cve CVE-2010-2941 JSON

CVE-2010-2941

9.8
CRITICAL · CVSS 3.1 · EPSS 6.4% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.42% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-416
On CISA KEVno
Public exploitnone known
Published2010-11-05
Last modified2026-06-16

Affected (13)

VendorProduct
applecups
applemac os x
applemac os x server
canonicalubuntu linux
debiandebian linux
fedoraprojectfedora
opensuseopensuse
redhatenterprise linux
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux workstation
suselinux enterprise
suselinux enterprise server

References

→ the Explorer  ·  watch your stack  ·  NVD