← Back

Xerox

xerox

119 CVEs • 299 products

Products (299)

Click to collapse
Toggle
Workcentre
workcentre
Freeflow Core
freeflow_core
Docutech 6110
docutech_6110
Docutech 6115
docutech_6115
Workcentre 65
workcentre_65
Workcentre 75
workcentre_75
Workcentre 90
workcentre_90

CVEs (119)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Xerox
1Phaser 3320 Firmware
Nov 21, 2024
Mar 13, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the attributes parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of...Show more
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the attributes parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS) and potentially execute arbitrary code on the device.Show less
1Xerox
1Phaser 3320 Firmware
Nov 21, 2024
Mar 13, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple Stored XSS vulnerabilities were found in the Xerox Web Application, used by the Phaser 3320 V53.006.16.000 and other printers. Successful exploitation of this vulnerability can lead to session hijacking of the a...Show more
Multiple Stored XSS vulnerabilities were found in the Xerox Web Application, used by the Phaser 3320 V53.006.16.000 and other printers. Successful exploitation of this vulnerability can lead to session hijacking of the administrator in the web application or the execution of unwanted actions.Show less
1Xerox
1Phaser 3320 Firmware
Nov 21, 2024
Mar 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement account lockout. Local account credentials may be extracted from the device via brute force guessing attacks.
1Xerox
1Phaser 3320 Firmware
Nov 21, 2024
Mar 13, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the request parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of Se...Show more
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the request parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS) and potentially execute arbitrary code on the device.Show less
1Xerox
18Workcentre 3655 Firmware
Workcentre 3655i FirmwareWorkcentre 5845 Firmware+15 more
Nov 21, 2024
Feb 21, 2020
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDAP connector IP address. A malicious actor who gains access to affected...Show more
Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDAP connector IP address. A malicious actor who gains access to affected devices (e.g., by using default credentials) can change the LDAP connection IP address to a system owned by the actor without knowledge of the LDAP bind credentials. After changing the LDAP connection IP address, subsequent authentication attempts will result in the printer sending plaintext LDAP (Active Directory) credentials to the actor. Although the credentials may belong to a non-privileged user, organizations frequently use privileged service accounts to bind to Active Directory. The attacker gains a foothold on the Active Directory domain at a minimum, and may use the credentials to take over control of the Active Directory domain. This affects 3655*, 3655i*, 58XX*, 58XXi*, 59XX*, 59XXi*, 6655**, 6655i**, 72XX*, 72XXi*, 78XX**, 78XXi**, 7970**, 7970i**, EC7836**, and EC7856** devices.Show less
1Xerox
12Colorqube 9201 Firmware
Colorqube 9202 FirmwareColorqube 9203 Firmware+9 more
Nov 21, 2024
Feb 13, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Xerox ColorCube and WorkCenter devices in 2013 had hardcoded FTP and shell user accounts.
1Xerox
1Altalink C8035 Firmware
Nov 21, 2024
Dec 18, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Xerox AltaLink C8035 printers allow CSRF. A request to add users is made in the Device User Database form field to the xerox.set URI. (The frmUserName value must have a unique name.)
1Xerox
1Atlalink Firmware
Nov 21, 2024
Oct 4, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Xerox AtlaLink B8045/B8055/B8065/B8075/B8090 C8030/C8035/C8045/C8055/C8070 printers with software before 101.00x.089.22600 allow an attacker to gain privileges.
1Xerox
1Colorqube 8580 Firmware
Nov 21, 2024
May 13, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) in the web interface of the Xerox ColorQube 8580 allows remote persistent injection of custom HTML / JavaScript code.
1Xerox
5Colorqube 8700 Firmware
Colorqube 8900 FirmwareColorqube 9301 Firmware+2 more
Nov 21, 2024
Apr 12, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depend...Show more
Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.Show less
1Xerox
29Workcentre 3655 Firmware
Workcentre 3655i FirmwareWorkcentre 5845 Firmware+26 more
Nov 21, 2024
Feb 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is unauthenticated...Show more
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is unauthenticated Remote Command Execution.Show less
1Xerox
29Workcentre 3655 Firmware
Workcentre 3655i FirmwareWorkcentre 5845 Firmware+26 more
Nov 21, 2024
Feb 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is Blind SQL Injec...Show more
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is Blind SQL Injection.Show less
1Xerox
29Workcentre 3655 Firmware
Workcentre 3655i FirmwareWorkcentre 5845 Firmware+26 more
Nov 21, 2024
Feb 10, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is a Local File In...Show more
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is a Local File Inclusion vulnerability.Show less
1Xerox
29Workcentre 3655 Firmware
Workcentre 3655i FirmwareWorkcentre 5845 Firmware+26 more
Nov 21, 2024
Feb 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. An attacker can execute...Show more
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. An attacker can execute PHP code by leveraging a writable file.Show less
1Xerox
29Workcentre 3655 Firmware
Workcentre 3655i FirmwareWorkcentre 5845 Firmware+26 more
Nov 21, 2024
Feb 10, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is authenticated r...Show more
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is authenticated remote command execution.Show less
1Xerox
10Altalink B8045 Firmware
Altalink B8055 FirmwareAltalink B8065 Firmware+7 more
Nov 21, 2024
Jan 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The web application on Xerox AltaLink B80xx before 100.008.028.05200, C8030/C8035 before 100.001.028.05200, C8045/C8055 before 100.002.028.05200, and C8070 before 100.003.028.05200 allows unauthenticated command injectio...Show more
The web application on Xerox AltaLink B80xx before 100.008.028.05200, C8030/C8035 before 100.001.028.05200, C8045/C8055 before 100.002.028.05200, and C8070 before 100.003.028.05200 allows unauthenticated command injection.Show less
1Xerox
1Docushare
May 6, 2026
May 2, 2014
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in Xerox DocuShare before 6.53 Patch 6 Hotfix 2, 6.6.1 Update 1 before Hotfix 24, and 6.6.1 Update 2 before Hotfix 3 allows remote authenticated users to execute arbitrary SQL commands via the...Show more
SQL injection vulnerability in Xerox DocuShare before 6.53 Patch 6 Hotfix 2, 6.6.1 Update 1 before Hotfix 24, and 6.6.1 Update 2 before Hotfix 3 allows remote authenticated users to execute arbitrary SQL commands via the PATH_INFO to /docushare/dsweb/ResultBackgroundJobMultiple/. NOTE: some of these details are obtained from third party information.Show less
2Sun
Xerox
2Freeflow Print Server
Sunos
Apr 29, 2026
Jan 17, 2013
N/A· v4
N/A· v3
6.0 MEDIUM· v2
Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the Bind/Postinstall script for Bind package.
2Sun
Xerox
2Freeflow Print Server
Sunos
Apr 29, 2026
Jan 17, 2013
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect availability via unknown vectors related to Kernel/DTrace Framework.
2Sun
Xerox
2Freeflow Print Server
Sunos
Apr 29, 2026
Jan 17, 2013
N/A· v4
N/A· v3
3.3 LOW· v2
Unspecified vulnerability Oracle Sun Solaris 10 allows local users to affect confidentiality and integrity via unknown vectors related to Install/smpatch.