Lexmark
lexmark
66 CVEs • 887 products
Products (887)
Click to collapseToggle
Products (887)
Click to collapse
CVEs (66)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Lexmark 25Cs31x Firmware Cs41x FirmwareCx310 Firmware+22 moreNov 21, 2024 Aug 28, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Various Lexmark products have Incorrect Access Control (issue 1 of 2). |
1Lexmark 746500e Firmware C734 FirmwareC736 Firmware+71 moreNov 21, 2024 Aug 28, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Various Lexmark products have Incorrect Access Control. |
1Lexmark 326500 Firmware Cx310 FirmwareCx410 Firmware+29 moreNov 21, 2024 Jun 28, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Various Lexmark devices have a Buffer Overflow (issue 1 of 2). |
1Lexmark 34Cx421 Firmware Cx522 FirmwareCx62x Firmware+31 moreNov 21, 2024 Jun 28, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Various Lexmark devices have a Buffer Overflow (issue 2 of 2). |
1Lexmark 8Cx725h Firmware Cx820 FirmwareCx825 Firmware+5 moreNov 21, 2024 Mar 12, 2019 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 On certain Lexmark devices that communicate with an LDAP or SMTP server, a malicious administrator can discover LDAP or SMTP credentials by changing that server's hostname to one that they control, and then capturing the...Show more |
1Lexmark 406500e Firmware Cx310 FirmwareCx410 Firmware+37 moreNov 21, 2024 Feb 11, 2019 N/A· v4 5.3 MEDIUM· v3 6.4 MEDIUM· v2 Certain Lexmark CX, MX, X, XC, XM, XS, and 6500e devices before 2019-02-11 allow remote attackers to erase stored shortcuts. |
Lexmark Scan To Network (SNF) 3.2.9 and earlier stores network configuration credentials in plaintext and transmits them in requests, which allows remote attackers to obtain sensitive information via requests to (1) cgi-...Show more |
1Lexmark 1Perceptive Document Filters May 13, 2026 Sep 5, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable code execution vulnerability exists in the image rendering functionality of Lexmark Perceptive Document Filters 11.3.0.2400. A specifically crafted PDF can cause a function call on a corrupted DCTStream to...Show more |
1Lexmark 1Perceptive Document Filters May 13, 2026 Sep 5, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable use-after-free exists in the PDF parsing functionality of Lexmark Perspective Document Filters 11.3.0.2400 and 11.4.0.2452. A crafted PDF document can lead to a use-after-free resulting in direct code exec...Show more |
1Lexmark 1Perceptive Document Filters May 13, 2026 Apr 20, 2017 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 An exploitable arbitrary read exists in the XLS parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted XLS document can lead to a arbitrary read resulting in memory disclosure. The vulner...Show more |
1Lexmark 1Perceptive Document Filters May 6, 2026 Jan 6, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable heap overflow vulnerability exists in the Compound Binary File Format (CBFF) parser functionality of Lexmark Perceptive Document Filters library. A specially crafted CBFF file can cause a code execution. A...Show more |
1Lexmark 1Perceptive Document Filters May 6, 2026 Jan 6, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An exploitable out-of-bounds write exists in the Bzip2 parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted Bzip2 document can lead to a stack-based buffer overflow causing an out-of-bo...Show more |
1Lexmark 1Perceptive Document Filters May 6, 2026 Jan 6, 2017 N/A· v4 8.4 HIGH· v3 6.8 MEDIUM· v2 An exploitable buffer overflow exists in the XLS parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted XLS document can lead to a stack based buffer overflow resulting in remote code exe...Show more |
Lexmark printers with firmware ATL before ATL.021.063, CB before CB.021.063, PP before PP.021.063, and YK before YK.021.063 mishandle Erase Printer Memory and Erase Hard Disk actions, which allows physically proximate at...Show more |
Race condition in the initialization process on Lexmark printers with firmware ATL before ATL.02.049, CB before CB.02.049, PP before PP.02.049, and YK before YK.02.049 allows remote attackers to bypass authentication by...Show more |
Directory traversal vulnerability in the LibraryFileUploadServlet servlet in Lexmark Markvision Enterprise allows remote authenticated users to write to and execute arbitrary files via a .. (dot dot) in a file path in a...Show more |
Multiple cross-site scripting (XSS) vulnerabilities on Lexmark W840 through LS.HA.P252, T64x before LS.ST.P344, C935dn through LC.JO.P091, C920 through LS.TA.P152, C53x through LS.SW.P069, C52x through LS.FA.P150, E450 t...Show more |
cgi-bin/postpf/cgi-bin/dynamic/config/config.html on Lexmark X94x before LC.BR.P142, X85x through LC4.BE.P487, X644 and X646 before LC2.MC.P374, X642 through LC2.MB.P318, W840 through LS.HA.P252, T64x before LS.ST.P344,...Show more |
Lexmark Markvision Enterprise before 1.8 provides a diagnostic interface on TCP port 9789, which allows remote attackers to execute arbitrary code, change the configuration, or obtain sensitive fleet-management informati...Show more |
The embedded HTTP server in multiple Lexmark laser and inkjet printers and MarkNet devices, including X94x, W840, T656, N4000, E462, C935dn, 25xxN, and other models, allows remote attackers to cause a denial of service (...Show more |