CVE-2015-1158
CVSS Score Not Available
74.07%
HIGH RiskEPSS (99th percentile)
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-host-name attributes, which allows remote attackers to trigger data corruption for reference-counted strings via a crafted (1) IPP_CREATE_JOB or (2) IPP_PRINT_JOB request, as demonstrated by replacing the configuration file and consequently executing arbitrary code.
Published: 6/26/2015
Modified: 4/12/2025
Vulnerability Summary
EPSS Score (Exploitation Probability)
74.07%HIGH Exploitation Risk
99th percentile
This vulnerability has a 74.07% probability of being exploited in the next 30 days, ranking higher than 99% of all scored CVEs.