Lexmark records
70 published records for vendor lexmark.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 3 · 4.3%
- Pre-auth RCE
- 11
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation8
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer8
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-306 Missing Authentication for Critical Function3
The weakness classes this vendor ships most often: where to look.
CWEAll records
70 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
62This week | CVE-2014-8741Weaponized | Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers lexmark · markvision enterprise · CWE-22 | Critical9.8 | — | 77.2% | Jan 27, 2020 |
43Plan | CVE-2023-26067Proof of concept | Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).lexmark · cxtpc firmware · CWE-20 | High8.1 | — | 37.8% | Apr 10, 2023 |
43Plan | CVE-2023-23560No exploit | In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.lexmark · b2236 firmware · CWE-918 | Critical9.8 | — | 13.9% | Jan 23, 2023 |
42Plan | CVE-2023-26068Weaponized | Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).lexmark · cxtpc firmware · CWE-20 | Critical9.8 | — | 11.6% | Apr 10, 2023 |
41Plan | CVE-2021-44735No exploit | Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.lexmark · b2236 firmware · CWE-77 | Critical9.8 | — | 7.0% | Jan 20, 2022 |
41Plan | CVE-2021-44734No exploit | Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code executiolexmark · b2236 firmware · CWE-94 | Critical9.8 | — | 6.4% | Jan 20, 2022 |
41Plan | CVE-2013-6032No exploit | cgi-bin/postpf/cgi-bin/dynamic/config/config.html on Lexmark X94x before LC.BR.P142, X85x through LC4.BE.P487, X644 and X646 before LC2.MC.Plexmark · 25xxn · CWE-20 | Critical10.0 | — | 3.3% | Feb 4, 2014 |
40Plan | CVE-2016-4336No exploit | An exploitable out-of-bounds write exists in the Bzip2 parsing of the Lexmark Perspective Document Filters conversion functionality.lexmark · perceptive document filters · CWE-787 | Critical9.8 | — | 3.8% | Jan 6, 2017 |
40Plan | CVE-2017-13771No exploit | Lexmark Scan To Network (SNF) 3.2.9 and earlier stores network configuration credentials in plaintext and transmits them in requests, which lexmark · scan to network · CWE-522 | Critical9.8 | — | 3.4% | Sep 7, 2017 |
40Plan | CVE-2021-44738No exploit | Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.lexmark · b2236 firmware · CWE-120 | Critical9.8 | — | 3.3% | Jan 20, 2022 |
40Plan | CVE-2016-1896No exploit | Race condition in the initialization process on Lexmark printers with firmware ATL before ATL.02.049, CB before CB.02.049, PP before PP.02.0lexmark · printer firmware · CWE-254 | Critical9.8 | — | 3.3% | Jan 27, 2016 |
40Plan | CVE-2021-44736No exploit | The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” feature.lexmark · mc3224i firmware · CWE-287 | Critical9.8 | — | 2.2% | Jan 20, 2022 |
40Plan | CVE-2016-6918No exploit | Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files.lexmark · markvision enterprise · CWE-434 | Critical9.8 | — | 1.9% | Mar 9, 2020 |
39Monitor | CVE-2019-9930No exploit | Various Lexmark products have an Integer Overflow.lexmark · cs31x firmware · CWE-190 | Critical9.8 | — | 1.5% | Aug 28, 2019 |
39Monitor | CVE-2019-9933No exploit | Various Lexmark products have a Buffer Overflow (issue 3 of 3).lexmark · cs31x firmware · CWE-119 | Critical9.8 | — | 1.5% | Aug 28, 2019 |
39Monitor | CVE-2019-9932No exploit | Various Lexmark products have a Buffer Overflow (issue 2 of 3).lexmark · cs31x firmware · CWE-119 | Critical9.8 | — | 1.5% | Aug 28, 2019 |
39Monitor | CVE-2018-15519No exploit | Various Lexmark devices have a Buffer Overflow (issue 1 of 2).lexmark · cx310 firmware · CWE-119 | Critical9.8 | — | 1.2% | Jun 28, 2019 |
39Monitor | CVE-2018-15520No exploit | Various Lexmark devices have a Buffer Overflow (issue 2 of 2).lexmark · cx82x firmware · CWE-119 | Critical9.8 | — | 1.2% | Jun 28, 2019 |
39Monitor | CVE-2023-26066No exploit | Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.lexmark · cxtpc firmware · CWE-129 | Critical9.8 | — | 0.7% | Apr 10, 2023 |
39Monitor | CVE-2023-26063No exploit | Certain Lexmark devices through 2023-02-19 access a Resource By Using an Incompatible Type.lexmark · cxtpc firmware · CWE-843 | Critical9.8 | — | 0.7% | Apr 10, 2023 |
39Monitor | CVE-2023-26064No exploit | Certain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.lexmark · cxtpc firmware · CWE-787 | Critical9.8 | — | 0.7% | Apr 10, 2023 |
39Monitor | CVE-2023-26065No exploit | Certain Lexmark devices through 2023-02-19 have an Integer Overflow.lexmark · cxtpc firmware · CWE-190 | Critical9.8 | — | 0.7% | Apr 10, 2023 |
39Monitor | CVE-2023-26069No exploit | Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4).lexmark · cxtpc firmware · CWE-20 | Critical9.8 | — | 0.7% | Apr 10, 2023 |
39Monitor | CVE-2023-26070No exploit | Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).lexmark · cxtpc firmware · CWE-20 | Critical9.8 | — | 0.7% | Apr 10, 2023 |
38Monitor | CVE-2023-22960Proof of concept | Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.lexmark · b2236 firmware · CWE-307 | High7.5 | — | 27.8% | Jan 23, 2023 |
- CVE-2014-874162This week
Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers
CriticalCVSS 9.8WeaponizedEPSS 77%lexmark · markvision enterpriseJan 27, 2020
- CVE-2023-2606743Plan
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
HighCVSS 8.1Proof of conceptEPSS 38%lexmark · cxtpc firmwareApr 10, 2023
- CVE-2023-2356043Plan
In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.
CriticalCVSS 9.8No exploitEPSS 14%lexmark · b2236 firmwareJan 23, 2023
- CVE-2023-2606842Plan
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).
CriticalCVSS 9.8WeaponizedEPSS 12%lexmark · cxtpc firmwareApr 10, 2023
- CVE-2021-4473541Plan
Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.
CriticalCVSS 9.8No exploitEPSS 7%lexmark · b2236 firmwareJan 20, 2022
- CVE-2021-4473441Plan
Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code executio
CriticalCVSS 9.8No exploitEPSS 6%lexmark · b2236 firmwareJan 20, 2022
- CVE-2013-603241Plan
cgi-bin/postpf/cgi-bin/dynamic/config/config.html on Lexmark X94x before LC.BR.P142, X85x through LC4.BE.P487, X644 and X646 before LC2.MC.P
CriticalCVSS 10.0No exploitEPSS 3%lexmark · 25xxnFeb 4, 2014
- CVE-2016-433640Plan
An exploitable out-of-bounds write exists in the Bzip2 parsing of the Lexmark Perspective Document Filters conversion functionality.
CriticalCVSS 9.8No exploitEPSS 4%lexmark · perceptive document filtersJan 6, 2017
- CVE-2017-1377140Plan
Lexmark Scan To Network (SNF) 3.2.9 and earlier stores network configuration credentials in plaintext and transmits them in requests, which
CriticalCVSS 9.8No exploitEPSS 3%lexmark · scan to networkSep 7, 2017
- CVE-2021-4473840Plan
Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.
CriticalCVSS 9.8No exploitEPSS 3%lexmark · b2236 firmwareJan 20, 2022
- CVE-2016-189640Plan
Race condition in the initialization process on Lexmark printers with firmware ATL before ATL.02.049, CB before CB.02.049, PP before PP.02.0
CriticalCVSS 9.8No exploitEPSS 3%lexmark · printer firmwareJan 27, 2016
- CVE-2021-4473640Plan
The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” feature.
CriticalCVSS 9.8No exploitEPSS 2%lexmark · mc3224i firmwareJan 20, 2022
- CVE-2016-691840Plan
Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files.
CriticalCVSS 9.8No exploitEPSS 2%lexmark · markvision enterpriseMar 9, 2020
- CVE-2019-993039Monitor
Various Lexmark products have an Integer Overflow.
CriticalCVSS 9.8No exploitEPSS 2%lexmark · cs31x firmwareAug 28, 2019
- CVE-2019-993339Monitor
Various Lexmark products have a Buffer Overflow (issue 3 of 3).
CriticalCVSS 9.8No exploitEPSS 2%lexmark · cs31x firmwareAug 28, 2019
- CVE-2019-993239Monitor
Various Lexmark products have a Buffer Overflow (issue 2 of 3).
CriticalCVSS 9.8No exploitEPSS 2%lexmark · cs31x firmwareAug 28, 2019
- CVE-2018-1551939Monitor
Various Lexmark devices have a Buffer Overflow (issue 1 of 2).
CriticalCVSS 9.8No exploitEPSS 1%lexmark · cx310 firmwareJun 28, 2019
- CVE-2018-1552039Monitor
Various Lexmark devices have a Buffer Overflow (issue 2 of 2).
CriticalCVSS 9.8No exploitEPSS 1%lexmark · cx82x firmwareJun 28, 2019
- CVE-2023-2606639Monitor
Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.
CriticalCVSS 9.8No exploitEPSS 1%lexmark · cxtpc firmwareApr 10, 2023
- CVE-2023-2606339Monitor
Certain Lexmark devices through 2023-02-19 access a Resource By Using an Incompatible Type.
CriticalCVSS 9.8No exploitEPSS 1%lexmark · cxtpc firmwareApr 10, 2023
- CVE-2023-2606439Monitor
Certain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.
CriticalCVSS 9.8No exploitEPSS 1%lexmark · cxtpc firmwareApr 10, 2023
- CVE-2023-2606539Monitor
Certain Lexmark devices through 2023-02-19 have an Integer Overflow.
CriticalCVSS 9.8No exploitEPSS 1%lexmark · cxtpc firmwareApr 10, 2023
- CVE-2023-2606939Monitor
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4).
CriticalCVSS 9.8No exploitEPSS 1%lexmark · cxtpc firmwareApr 10, 2023
- CVE-2023-2607039Monitor
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).
CriticalCVSS 9.8No exploitEPSS 1%lexmark · cxtpc firmwareApr 10, 2023
- CVE-2023-2296038Monitor
Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.
HighCVSS 7.5Proof of conceptEPSS 28%lexmark · b2236 firmwareJan 23, 2023