CVE-2014-8166: Cups

High severity, CVSS 8.8. EPSS: 3.7% chance of exploitation in the next 30 days.

The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to execute arbitrary code via a crafted printer name.

Affected products

  • Cups Cups: before 1.6 (fixed in 1.6)

Published 2018-01-12. Last modified 2026-06-17.