Xerox
xerox
119 CVEs • 299 products
Products (299)
Click to collapseToggle
Products (299)
Click to collapse
CVEs (119)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Xerox 1Phaser 3320 Firmware Nov 21, 2024 Mar 13, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the attributes parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of...Show more |
1Xerox 1Phaser 3320 Firmware Nov 21, 2024 Mar 13, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple Stored XSS vulnerabilities were found in the Xerox Web Application, used by the Phaser 3320 V53.006.16.000 and other printers. Successful exploitation of this vulnerability can lead to session hijacking of the a...Show more |
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement account lockout. Local account credentials may be extracted from the device via brute force guessing attacks. |
1Xerox 1Phaser 3320 Firmware Nov 21, 2024 Mar 13, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the request parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of Se...Show more |
1Xerox 18Workcentre 3655 Firmware Workcentre 3655i FirmwareWorkcentre 5845 Firmware+15 moreNov 21, 2024 Feb 21, 2020 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDAP connector IP address. A malicious actor who gains access to affected...Show more |
1Xerox 12Colorqube 9201 Firmware Colorqube 9202 FirmwareColorqube 9203 Firmware+9 moreNov 21, 2024 Feb 13, 2020 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Xerox ColorCube and WorkCenter devices in 2013 had hardcoded FTP and shell user accounts. |
1Xerox 1Altalink C8035 Firmware Nov 21, 2024 Dec 18, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Xerox AltaLink C8035 printers allow CSRF. A request to add users is made in the Device User Database form field to the xerox.set URI. (The frmUserName value must have a unique name.) |
Xerox AtlaLink B8045/B8055/B8065/B8075/B8090 C8030/C8035/C8045/C8055/C8070 printers with software before 101.00x.089.22600 allow an attacker to gain privileges. |
1Xerox 1Colorqube 8580 Firmware Nov 21, 2024 May 13, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) in the web interface of the Xerox ColorQube 8580 allows remote persistent injection of custom HTML / JavaScript code. |
1Xerox 5Colorqube 8700 Firmware Colorqube 8900 FirmwareColorqube 9301 Firmware+2 moreNov 21, 2024 Apr 12, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depend...Show more |
1Xerox 29Workcentre 3655 Firmware Workcentre 3655i FirmwareWorkcentre 5845 Firmware+26 moreNov 21, 2024 Feb 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is unauthenticated...Show more |
1Xerox 29Workcentre 3655 Firmware Workcentre 3655i FirmwareWorkcentre 5845 Firmware+26 moreNov 21, 2024 Feb 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is Blind SQL Injec...Show more |
1Xerox 29Workcentre 3655 Firmware Workcentre 3655i FirmwareWorkcentre 5845 Firmware+26 moreNov 21, 2024 Feb 10, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is a Local File In...Show more |
1Xerox 29Workcentre 3655 Firmware Workcentre 3655i FirmwareWorkcentre 5845 Firmware+26 moreNov 21, 2024 Feb 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. An attacker can execute...Show more |
1Xerox 29Workcentre 3655 Firmware Workcentre 3655i FirmwareWorkcentre 5845 Firmware+26 moreNov 21, 2024 Feb 10, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is authenticated r...Show more |
1Xerox 10Altalink B8045 Firmware Altalink B8055 FirmwareAltalink B8065 Firmware+7 moreNov 21, 2024 Jan 3, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The web application on Xerox AltaLink B80xx before 100.008.028.05200, C8030/C8035 before 100.001.028.05200, C8045/C8055 before 100.002.028.05200, and C8070 before 100.003.028.05200 allows unauthenticated command injectio...Show more |
SQL injection vulnerability in Xerox DocuShare before 6.53 Patch 6 Hotfix 2, 6.6.1 Update 1 before Hotfix 24, and 6.6.1 Update 2 before Hotfix 3 allows remote authenticated users to execute arbitrary SQL commands via the...Show more |
2Sun Xerox2Freeflow Print Server SunosApr 29, 2026 Jan 17, 2013 N/A· v4 N/A· v3 6.0 MEDIUM· v2 Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the Bind/Postinstall script for Bind package. |
2Sun Xerox2Freeflow Print Server SunosApr 29, 2026 Jan 17, 2013 N/A· v4 N/A· v3 4.6 MEDIUM· v2 Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect availability via unknown vectors related to Kernel/DTrace Framework. |
Unspecified vulnerability Oracle Sun Solaris 10 allows local users to affect confidentiality and integrity via unknown vectors related to Install/smpatch. |