Записи lexmark
70 опубликованных записей вендора lexmark.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 3 · 4,3 %
- Pre-auth RCE
- 11
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation8
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer8
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-306 Missing Authentication for Critical Function3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
70 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
62На этой неделе | CVE-2014-8741Готовый эксплойт | Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers lexmark · markvision enterprise · CWE-22 | Критическая9,8 | — | 77,2 % | 27 янв. 2020 г. |
43В плане | CVE-2023-26067Proof of concept | Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).lexmark · cxtpc firmware · CWE-20 | Высокая8,1 | — | 37,8 % | 10 апр. 2023 г. |
43В плане | CVE-2023-23560Эксплойта нет | In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.lexmark · b2236 firmware · CWE-918 | Критическая9,8 | — | 13,9 % | 23 янв. 2023 г. |
42В плане | CVE-2023-26068Готовый эксплойт | Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).lexmark · cxtpc firmware · CWE-20 | Критическая9,8 | — | 11,6 % | 10 апр. 2023 г. |
41В плане | CVE-2021-44735Эксплойта нет | Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.lexmark · b2236 firmware · CWE-77 | Критическая9,8 | — | 7,0 % | 20 янв. 2022 г. |
41В плане | CVE-2021-44734Эксплойта нет | Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code executiolexmark · b2236 firmware · CWE-94 | Критическая9,8 | — | 6,4 % | 20 янв. 2022 г. |
41В плане | CVE-2013-6032Эксплойта нет | cgi-bin/postpf/cgi-bin/dynamic/config/config.html on Lexmark X94x before LC.BR.P142, X85x through LC4.BE.P487, X644 and X646 before LC2.MC.Plexmark · 25xxn · CWE-20 | Критическая10,0 | — | 3,3 % | 4 февр. 2014 г. |
40В плане | CVE-2016-4336Эксплойта нет | An exploitable out-of-bounds write exists in the Bzip2 parsing of the Lexmark Perspective Document Filters conversion functionality.lexmark · perceptive document filters · CWE-787 | Критическая9,8 | — | 3,8 % | 6 янв. 2017 г. |
40В плане | CVE-2017-13771Эксплойта нет | Lexmark Scan To Network (SNF) 3.2.9 and earlier stores network configuration credentials in plaintext and transmits them in requests, which lexmark · scan to network · CWE-522 | Критическая9,8 | — | 3,4 % | 7 сент. 2017 г. |
40В плане | CVE-2021-44738Эксплойта нет | Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.lexmark · b2236 firmware · CWE-120 | Критическая9,8 | — | 3,3 % | 20 янв. 2022 г. |
40В плане | CVE-2016-1896Эксплойта нет | Race condition in the initialization process on Lexmark printers with firmware ATL before ATL.02.049, CB before CB.02.049, PP before PP.02.0lexmark · printer firmware · CWE-254 | Критическая9,8 | — | 3,3 % | 27 янв. 2016 г. |
40В плане | CVE-2021-44736Эксплойта нет | The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” feature.lexmark · mc3224i firmware · CWE-287 | Критическая9,8 | — | 2,2 % | 20 янв. 2022 г. |
40В плане | CVE-2016-6918Эксплойта нет | Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files.lexmark · markvision enterprise · CWE-434 | Критическая9,8 | — | 1,9 % | 9 мар. 2020 г. |
39Наблюдать | CVE-2019-9930Эксплойта нет | Various Lexmark products have an Integer Overflow.lexmark · cs31x firmware · CWE-190 | Критическая9,8 | — | 1,5 % | 28 авг. 2019 г. |
39Наблюдать | CVE-2019-9933Эксплойта нет | Various Lexmark products have a Buffer Overflow (issue 3 of 3).lexmark · cs31x firmware · CWE-119 | Критическая9,8 | — | 1,5 % | 28 авг. 2019 г. |
39Наблюдать | CVE-2019-9932Эксплойта нет | Various Lexmark products have a Buffer Overflow (issue 2 of 3).lexmark · cs31x firmware · CWE-119 | Критическая9,8 | — | 1,5 % | 28 авг. 2019 г. |
39Наблюдать | CVE-2018-15519Эксплойта нет | Various Lexmark devices have a Buffer Overflow (issue 1 of 2).lexmark · cx310 firmware · CWE-119 | Критическая9,8 | — | 1,2 % | 28 июн. 2019 г. |
39Наблюдать | CVE-2018-15520Эксплойта нет | Various Lexmark devices have a Buffer Overflow (issue 2 of 2).lexmark · cx82x firmware · CWE-119 | Критическая9,8 | — | 1,2 % | 28 июн. 2019 г. |
39Наблюдать | CVE-2023-26066Эксплойта нет | Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.lexmark · cxtpc firmware · CWE-129 | Критическая9,8 | — | 0,7 % | 10 апр. 2023 г. |
39Наблюдать | CVE-2023-26063Эксплойта нет | Certain Lexmark devices through 2023-02-19 access a Resource By Using an Incompatible Type.lexmark · cxtpc firmware · CWE-843 | Критическая9,8 | — | 0,7 % | 10 апр. 2023 г. |
39Наблюдать | CVE-2023-26064Эксплойта нет | Certain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.lexmark · cxtpc firmware · CWE-787 | Критическая9,8 | — | 0,7 % | 10 апр. 2023 г. |
39Наблюдать | CVE-2023-26065Эксплойта нет | Certain Lexmark devices through 2023-02-19 have an Integer Overflow.lexmark · cxtpc firmware · CWE-190 | Критическая9,8 | — | 0,7 % | 10 апр. 2023 г. |
39Наблюдать | CVE-2023-26069Эксплойта нет | Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4).lexmark · cxtpc firmware · CWE-20 | Критическая9,8 | — | 0,7 % | 10 апр. 2023 г. |
39Наблюдать | CVE-2023-26070Эксплойта нет | Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).lexmark · cxtpc firmware · CWE-20 | Критическая9,8 | — | 0,7 % | 10 апр. 2023 г. |
38Наблюдать | CVE-2023-22960Proof of concept | Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.lexmark · b2236 firmware · CWE-307 | Высокая7,5 | — | 27,8 % | 23 янв. 2023 г. |
- CVE-2014-874162На этой неделе
Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers
КритическаяCVSS 9,8Готовый эксплойтEPSS 77 %lexmark · markvision enterprise27 янв. 2020 г.
- CVE-2023-2606743В плане
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
ВысокаяCVSS 8,1Proof of conceptEPSS 38 %lexmark · cxtpc firmware10 апр. 2023 г.
- CVE-2023-2356043В плане
In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.
КритическаяCVSS 9,8Эксплойта нетEPSS 14 %lexmark · b2236 firmware23 янв. 2023 г.
- CVE-2023-2606842В плане
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).
КритическаяCVSS 9,8Готовый эксплойтEPSS 12 %lexmark · cxtpc firmware10 апр. 2023 г.
- CVE-2021-4473541В плане
Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %lexmark · b2236 firmware20 янв. 2022 г.
- CVE-2021-4473441В плане
Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code executio
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %lexmark · b2236 firmware20 янв. 2022 г.
- CVE-2013-603241В плане
cgi-bin/postpf/cgi-bin/dynamic/config/config.html on Lexmark X94x before LC.BR.P142, X85x through LC4.BE.P487, X644 and X646 before LC2.MC.P
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %lexmark · 25xxn4 февр. 2014 г.
- CVE-2016-433640В плане
An exploitable out-of-bounds write exists in the Bzip2 parsing of the Lexmark Perspective Document Filters conversion functionality.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %lexmark · perceptive document filters6 янв. 2017 г.
- CVE-2017-1377140В плане
Lexmark Scan To Network (SNF) 3.2.9 and earlier stores network configuration credentials in plaintext and transmits them in requests, which
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %lexmark · scan to network7 сент. 2017 г.
- CVE-2021-4473840В плане
Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %lexmark · b2236 firmware20 янв. 2022 г.
- CVE-2016-189640В плане
Race condition in the initialization process on Lexmark printers with firmware ATL before ATL.02.049, CB before CB.02.049, PP before PP.02.0
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %lexmark · printer firmware27 янв. 2016 г.
- CVE-2021-4473640В плане
The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” feature.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %lexmark · mc3224i firmware20 янв. 2022 г.
- CVE-2016-691840В плане
Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %lexmark · markvision enterprise9 мар. 2020 г.
- CVE-2019-993039Наблюдать
Various Lexmark products have an Integer Overflow.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %lexmark · cs31x firmware28 авг. 2019 г.
- CVE-2019-993339Наблюдать
Various Lexmark products have a Buffer Overflow (issue 3 of 3).
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %lexmark · cs31x firmware28 авг. 2019 г.
- CVE-2019-993239Наблюдать
Various Lexmark products have a Buffer Overflow (issue 2 of 3).
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %lexmark · cs31x firmware28 авг. 2019 г.
- CVE-2018-1551939Наблюдать
Various Lexmark devices have a Buffer Overflow (issue 1 of 2).
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %lexmark · cx310 firmware28 июн. 2019 г.
- CVE-2018-1552039Наблюдать
Various Lexmark devices have a Buffer Overflow (issue 2 of 2).
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %lexmark · cx82x firmware28 июн. 2019 г.
- CVE-2023-2606639Наблюдать
Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %lexmark · cxtpc firmware10 апр. 2023 г.
- CVE-2023-2606339Наблюдать
Certain Lexmark devices through 2023-02-19 access a Resource By Using an Incompatible Type.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %lexmark · cxtpc firmware10 апр. 2023 г.
- CVE-2023-2606439Наблюдать
Certain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %lexmark · cxtpc firmware10 апр. 2023 г.
- CVE-2023-2606539Наблюдать
Certain Lexmark devices through 2023-02-19 have an Integer Overflow.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %lexmark · cxtpc firmware10 апр. 2023 г.
- CVE-2023-2606939Наблюдать
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4).
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %lexmark · cxtpc firmware10 апр. 2023 г.
- CVE-2023-2607039Наблюдать
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %lexmark · cxtpc firmware10 апр. 2023 г.
- CVE-2023-2296038Наблюдать
Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.
ВысокаяCVSS 7,5Proof of conceptEPSS 28 %lexmark · b2236 firmware23 янв. 2023 г.