Xerox
xerox
119 CVEs • 299 products
Products (299)
Click to collapseToggle
Products (299)
Click to collapse
CVEs (119)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A persistent cross-site scripting (XSS) vulnerability exists on two input fields within the administrative panel when editing users in the XMPie UStore application on version 12.3.7244.0. |
XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and...Show more |
Xerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device via a crafted TIFF file in an unauthenticated HTTP POST request. There is a permanent denial of servic...Show more |
1Xerox 10Altalink B8045 Firmware Altalink B8055 FirmwareAltalink B8065 Firmware+7 moreNov 21, 2024 Apr 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Xerox AltaLink B8045/B8055/B8065/B8075/B8090, AltaLink C8030/C8035/C8045/C8055/C8070 with software releases before 103.xxx.030.32000 includes two accounts with weak hard-coded passwords which can be exploited and allow u...Show more |
1Xerox 24Phaser 6510 Firmware Versalink B400 FirmwareVersalink B405 Firmware+21 moreNov 21, 2024 Mar 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Xerox Phaser 6510 before 64.65.51 and 64.59.11 (Bridge), WorkCentre 6515 before 65.65.51 and 65.59.11 (Bridge), VersaLink B400 before 37.65.51 and 37.59.01 (Bridge), B405 before 38.65.51 and 38.59.01 (Bridge), B600/B610...Show more |
1Xerox 24Phaser 6510 Firmware Versalink B400 FirmwareVersalink B405 Firmware+21 moreNov 21, 2024 Mar 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Xerox Phaser 6510 before 64.65.51 and 64.59.11 (Bridge), WorkCentre 6515 before 65.65.51 and 65.59.11 (Bridge), VersaLink B400 before 37.65.51 and 37.59.01 (Bridge), B405 before 38.65.51 and 38.59.01 (Bridge), B600/B610...Show more |
1Xerox 23Phaser 6510 Firmware Versalink B400 FirmwareVersalink B405 Firmware+20 moreNov 21, 2024 Mar 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Xerox Phaser 6510 before 64.61.23 and 64.59.11 (Bridge), WorkCentre 6515 before 65.61.23 and 65.59.11 (Bridge), VersaLink B400 before 37.61.23 and 37.59.01 (Bridge), B405 before 38.61.23 and 38.59.01 (Bridge), B600/B610...Show more |
1Xerox 10Altalink B8045 Firmware Altalink B8055 FirmwareAltalink B8065 Firmware+7 moreNov 21, 2024 Mar 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 before 103.001.020.23120, C8045/C8055 before 103.002.020.23120 and C8070 before 103.003.020.23120 provide the ability to set configuration attributes without adm...Show more |
1Xerox 10Altalink B8045 Firmware Altalink B8055 FirmwareAltalink B8065 Firmware+7 moreNov 21, 2024 Mar 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 before 103.001.020.23120, C8045/C8055 before 103.002.020.23120 and C8070 before 103.003.020.23120 has several SQL injection vulnerabilities. |
1Xerox 10Altalink B8045 Firmware Altalink B8055 FirmwareAltalink B8065 Firmware+7 moreNov 21, 2024 Mar 29, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Xerox AltaLink B8045/B8090 before 103.008.030.32000, C8030/C8035 before 103.001.030.32000, C8045/C8055 before 103.002.030.32000 and C8070 before 103.003.030.32000 allow unauthorized users, by leveraging the Scan To Mailb...Show more |
1Xerox 10Altalink B8045 Firmware Altalink B8055 FirmwareAltalink B8065 Firmware+7 moreNov 21, 2024 Mar 4, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 On Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200, portions of the drive containing executable code were not encrypte...Show more |
1Xerox 10Altalink B8045 Firmware Altalink B8055 FirmwareAltalink B8065 Firmware+7 moreNov 21, 2024 Mar 4, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200 allow an attacker to execute an unwanted binary during a exploited clo...Show more |
1Xerox 10Altalink B8045 Firmware Altalink B8055 FirmwareAltalink B8065 Firmware+7 moreNov 21, 2024 Mar 4, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200 allow a user with administrative privileges to turn off data encryptio...Show more |
1Xerox 30Workcentre 3655 Firmware Workcentre 3655i FirmwareWorkcentre 5865 Firmware+27 moreNov 21, 2024 Jan 26, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in certain Xerox WorkCentre products. They do not properly encrypt passwords. This affects 3655, 3655i, 58XX, 58XXi 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi 78XX, 78XXi, 7970, 7970i, EC7836, and EC78...Show more |
1Xerox 2Workcentre Ec7836 Firmware Workcentre Ec7856 FirmwareNov 21, 2024 Oct 9, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Xerox WorkCentre EC7836 before 073.050.059.25300 and EC7856 before 073.020.059.25300 devices allow XSS via Description pages. |
1Xerox 25Workcentre 3655 Firmware Workcentre 3655i FirmwareWorkcentre 5865 Firmware+22 moreNov 21, 2024 Apr 29, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410 do not properly escape parameters in the support/remoteUI/configrui.php scri...Show more |
1Xerox 1Phaser 3320 Firmware Nov 21, 2024 Mar 13, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Authentication Cookie of the web application that would allow an attacker to execute arbitrary code on...Show more |
1Xerox 1Phaser 3320 Firmware Nov 21, 2024 Mar 13, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by one or more stack-based buffer overflow vulnerabilities in the Google Cloud Print implementation that would allow an unauthenticated attacker...Show more |
1Xerox 1Phaser 3320 Firmware Nov 21, 2024 Mar 13, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement any mechanism to avoid CSRF attacks. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device. |
1Xerox 1Phaser 3320 Firmware Nov 21, 2024 Mar 13, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Content-Type HTTP Header of the web application that would allow an attacker to execute arbitrary code...Show more |