RICOH kayıtları
ricoh üreticisine ait 46 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %4,3
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %2,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')15
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer6
- CWE-798 Use of Hard-coded Credentials4
- CWE-787 Out-of-bounds Write3
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
- CWE-345 Insufficient Verification of Data Authenticity1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
46 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
45Planlayın | CVE-2018-18006İstismar yok | Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any externally disclosed myPricoh · myprint · CWE-798 | Kritik9,8 | — | %21,5 | 14 Ara 2018 |
40Planlayın | CVE-2018-16184İstismar yok | RICOH Interactive Whiteboard D2200 V1.6 to V2.2, D5500 V1.6 to V2.2, D5510 V1.6 to V2.2, and the display versions with RICOH Interactive Whiricoh · d2200 firmware · CWE-78 | Kritik9,8 | — | %4,3 | 9 Oca 2019 |
40Planlayın | CVE-2019-14300İstismar yok | Several Ricoh printers have multiple buffer overflows parsing HTTP cookie headers, which allow an attacker to cause a denial of service or cricoh · sp c250sf firmware · CWE-119 | Kritik9,8 | — | %3,1 | 26 Ağu 2019 |
40Planlayın | CVE-2019-14308İstismar yok | Several Ricoh printers have multiple buffer overflows parsing LPD packets, which allow an attacker to cause a denial of service or code execricoh · sp c250sf firmware · CWE-119 | Kritik9,8 | — | %3,1 | 26 Ağu 2019 |
40Planlayın | CVE-2019-14307İstismar yok | Several Ricoh printers have multiple buffer overflows parsing HTTP parameter settings for SNMP, which allow an attacker to cause a denial ofricoh · sp c250sf firmware · CWE-119 | Kritik9,8 | — | %3,0 | 26 Ağu 2019 |
40Planlayın | CVE-2019-14305İstismar yok | Several Ricoh printers have multiple buffer overflows parsing HTTP parameter settings for Wi-Fi, mDNS, POP3, SMTP, and notification alerts, ricoh · sp c250sf firmware · CWE-119 | Kritik9,8 | — | %3,0 | 26 Ağu 2019 |
40Planlayın | CVE-2019-14310İstismar yok | Ricoh SP C250DN 1.05 devices allow denial of service (issue 2 of 3).ricoh · sp c250sf firmware · CWE-787 | Kritik9,8 | — | %1,9 | 13 Mar 2020 |
40Planlayın | CVE-2018-16188İstismar yok | SQL injection vulnerability in the RICOH Interactive Whiteboard D2200 V1.3 to V2.2, D5500 V1.3 to V2.2, D5510 V1.3 to V2.2, the display versricoh · d2200 firmware · CWE-89 | Kritik9,8 | — | %1,9 | 9 Oca 2019 |
40Planlayın | CVE-2021-33945İstismar yok | RICOH Printer series SP products 320DN, SP 325DNw, SP 320SN, SP 320SFN, SP 325SNw, SP 325SFNw, SP 330SN, Aficio SP 3500SF, SP 221S, SP 220SNricoh · sp 320dn firmware · CWE-787 | Kritik9,8 | — | %1,8 | 15 Şub 2022 |
39İzleyin | CVE-2019-14299İstismar yok | Ricoh SP C250DN 1.05 devices have an Authentication Method Vulnerable to Brute Force Attacks.ricoh · sp c250sf firmware · CWE-307 | Kritik9,8 | — | %1,4 | 13 Mar 2020 |
39İzleyin | CVE-2024-37124İstismar yok | Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client.ricoh company, ltd. · ricoh streamline nx pc client · CWE-94 | Kritik9,8 | — | %0,5 | 19 Haz 2024 |
39İzleyin | CVE-2024-36480İstismar yok | Use of hard-coded credentials issue exists in Ricoh Streamline NX PC Client ver.3.7.2 and earlier.cve-2024-36480 · ricoh streamline nx pc client · CWE-798 | Kritik9,8 | — | %0,4 | 19 Haz 2024 |
36İzleyin | CVE-2012-5002Silahlaştırılmış | Stack-based buffer overflow in SR10 FTP server (SR10.exe) 1.1.0.6 in Ricoh DC Software DL-10 4.5.0.1, when the Log file name option is enablricoh · dl-10 · CWE-119 | Orta6,8 | — | %31,2 | 19 Eyl 2012 |
36İzleyin | CVE-2018-15884Kavram kanıtı | RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.ricoh · mp c4504ex firmware · CWE-79 | Yüksek8,8 | — | %2,5 | 28 Ağu 2018 |
36İzleyin | CVE-2022-43969İstismar yok | Ricoh mp_c4504ex devices with firmware 1.06 mishandle credentials.ricoh · mp c307 firmware · CWE-522 | Kritik9,1 | — | %0,5 | 16 Şub 2023 |
35İzleyin | CVE-2019-14304İstismar yok | Ricoh SP C250DN 1.06 devices allow CSRF.ricoh · sp c250sf firmware · CWE-352 | Yüksek8,8 | — | %0,7 | 10 Oca 2020 |
35İzleyin | CVE-2018-16186İstismar yok | RICOH Interactive Whiteboard D2200 V1.1 to V2.2, D5500 V1.1 to V2.2, D5510 V1.1 to V2.2, the display versions with RICOH Interactive Whiteboricoh · d2200 firmware · CWE-798 | Yüksek8,8 | — | %0,6 | 9 Oca 2019 |
34İzleyin | CVE-2019-7751Kavram kanıtı | A directory traversal and local file inclusion vulnerability in FPProducerInternetServer.exe in Ricoh MarcomCentral, formerly PTI Marketing,ricoh · fusionpro vdp · CWE-22 | Yüksek7,5 | — | %14,2 | 31 Ara 2019 |
32İzleyin | CVE-2015-6750Kavram kanıtı | Buffer overflow in Ricoh DL FTP Server 1.1.0.6 and earlier allows remote attackers to execute arbitrary code via a long USER command.ricoh · dl-1 sr10 · CWE-119 | Yüksek7,5 | — | %7,7 | 31 Ağu 2015 |
32İzleyin | CVE-2019-19363Silahlaştırılmış | An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attackers local privilege esricoh · generic pcl5 driver · CWE-732 | Yüksek7,8 | — | %4,4 | 24 Oca 2020 |
32İzleyin | CVE-2024-39927İstismar yok | Out-of-bounds write vulnerability exists in Ricoh MFPs and printers.ricoh company, ltd. · im c3510/c3010 · CWE-787 | Yüksek8,2 | — | %0,6 | 10 Tem 2024 |
31İzleyin | CVE-2018-16185İstismar yok | RICOH Interactive Whiteboard D2200 V1.1 to V2.2, D5500 V1.1 to V2.2, D5510 V1.1 to V2.2, the display versions with RICOH Interactive Whiteboricoh · d2200 firmware · CWE-20 | Yüksek7,8 | — | %1,0 | 9 Oca 2019 |
31İzleyin | CVE-2019-20001İstismar yok | An issue was discovered in RICOH Streamline NX Client Tool and RICOH Streamline NX PC Client that allows attackers to escalate local privilericoh · streamline nx client tool | Yüksek7,8 | — | %0,3 | 4 Ağu 2020 |
31İzleyin | CVE-2022-36403İstismar yok | Untrusted search path vulnerability in the installer of Device Software Manager prior to Ver.2.20.3.0 allows an attacker to gain privileges ricoh · device software manager · CWE-426 | Yüksek7,8 | — | %0,2 | 8 Eyl 2022 |
31İzleyin | CVE-2023-30759İstismar yok | The driver installation package created by Printer Driver Packager NX v1.0.02 to v1.1.25 fails to detect its modification and may spawn an uricoh · printer driver packager nx · CWE-345 | Yüksek7,8 | — | %0,1 | 19 Haz 2023 |
- CVE-2018-1800645Planlayın
Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any externally disclosed myP
KritikCVSS 9,8İstismar yokEPSS %21ricoh · myprint14 Ara 2018
- CVE-2018-1618440Planlayın
RICOH Interactive Whiteboard D2200 V1.6 to V2.2, D5500 V1.6 to V2.2, D5510 V1.6 to V2.2, and the display versions with RICOH Interactive Whi
KritikCVSS 9,8İstismar yokEPSS %4ricoh · d2200 firmware9 Oca 2019
- CVE-2019-1430040Planlayın
Several Ricoh printers have multiple buffer overflows parsing HTTP cookie headers, which allow an attacker to cause a denial of service or c
KritikCVSS 9,8İstismar yokEPSS %3ricoh · sp c250sf firmware26 Ağu 2019
- CVE-2019-1430840Planlayın
Several Ricoh printers have multiple buffer overflows parsing LPD packets, which allow an attacker to cause a denial of service or code exec
KritikCVSS 9,8İstismar yokEPSS %3ricoh · sp c250sf firmware26 Ağu 2019
- CVE-2019-1430740Planlayın
Several Ricoh printers have multiple buffer overflows parsing HTTP parameter settings for SNMP, which allow an attacker to cause a denial of
KritikCVSS 9,8İstismar yokEPSS %3ricoh · sp c250sf firmware26 Ağu 2019
- CVE-2019-1430540Planlayın
Several Ricoh printers have multiple buffer overflows parsing HTTP parameter settings for Wi-Fi, mDNS, POP3, SMTP, and notification alerts,
KritikCVSS 9,8İstismar yokEPSS %3ricoh · sp c250sf firmware26 Ağu 2019
- CVE-2019-1431040Planlayın
Ricoh SP C250DN 1.05 devices allow denial of service (issue 2 of 3).
KritikCVSS 9,8İstismar yokEPSS %2ricoh · sp c250sf firmware13 Mar 2020
- CVE-2018-1618840Planlayın
SQL injection vulnerability in the RICOH Interactive Whiteboard D2200 V1.3 to V2.2, D5500 V1.3 to V2.2, D5510 V1.3 to V2.2, the display vers
KritikCVSS 9,8İstismar yokEPSS %2ricoh · d2200 firmware9 Oca 2019
- CVE-2021-3394540Planlayın
RICOH Printer series SP products 320DN, SP 325DNw, SP 320SN, SP 320SFN, SP 325SNw, SP 325SFNw, SP 330SN, Aficio SP 3500SF, SP 221S, SP 220SN
KritikCVSS 9,8İstismar yokEPSS %2ricoh · sp 320dn firmware15 Şub 2022
- CVE-2019-1429939İzleyin
Ricoh SP C250DN 1.05 devices have an Authentication Method Vulnerable to Brute Force Attacks.
KritikCVSS 9,8İstismar yokEPSS %1ricoh · sp c250sf firmware13 Mar 2020
- CVE-2024-3712439İzleyin
Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client.
KritikCVSS 9,8İstismar yokEPSS %1ricoh company, ltd. · ricoh streamline nx pc client19 Haz 2024
- CVE-2024-3648039İzleyin
Use of hard-coded credentials issue exists in Ricoh Streamline NX PC Client ver.3.7.2 and earlier.
KritikCVSS 9,8İstismar yokEPSS %0cve-2024-36480 · ricoh streamline nx pc client19 Haz 2024
- CVE-2012-500236İzleyin
Stack-based buffer overflow in SR10 FTP server (SR10.exe) 1.1.0.6 in Ricoh DC Software DL-10 4.5.0.1, when the Log file name option is enabl
OrtaCVSS 6,8SilahlaştırılmışEPSS %31ricoh · dl-1019 Eyl 2012
- CVE-2018-1588436İzleyin
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
YüksekCVSS 8,8Kavram kanıtıEPSS %3ricoh · mp c4504ex firmware28 Ağu 2018
- CVE-2022-4396936İzleyin
Ricoh mp_c4504ex devices with firmware 1.06 mishandle credentials.
KritikCVSS 9,1İstismar yokEPSS %1ricoh · mp c307 firmware16 Şub 2023
- CVE-2019-1430435İzleyin
Ricoh SP C250DN 1.06 devices allow CSRF.
YüksekCVSS 8,8İstismar yokEPSS %1ricoh · sp c250sf firmware10 Oca 2020
- CVE-2018-1618635İzleyin
RICOH Interactive Whiteboard D2200 V1.1 to V2.2, D5500 V1.1 to V2.2, D5510 V1.1 to V2.2, the display versions with RICOH Interactive Whitebo
YüksekCVSS 8,8İstismar yokEPSS %1ricoh · d2200 firmware9 Oca 2019
- CVE-2019-775134İzleyin
A directory traversal and local file inclusion vulnerability in FPProducerInternetServer.exe in Ricoh MarcomCentral, formerly PTI Marketing,
YüksekCVSS 7,5Kavram kanıtıEPSS %14ricoh · fusionpro vdp31 Ara 2019
- CVE-2015-675032İzleyin
Buffer overflow in Ricoh DL FTP Server 1.1.0.6 and earlier allows remote attackers to execute arbitrary code via a long USER command.
YüksekCVSS 7,5Kavram kanıtıEPSS %8ricoh · dl-1 sr1031 Ağu 2015
- CVE-2019-1936332İzleyin
An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attackers local privilege es
YüksekCVSS 7,8SilahlaştırılmışEPSS %4ricoh · generic pcl5 driver24 Oca 2020
- CVE-2024-3992732İzleyin
Out-of-bounds write vulnerability exists in Ricoh MFPs and printers.
YüksekCVSS 8,2İstismar yokEPSS %1ricoh company, ltd. · im c3510/c301010 Tem 2024
- CVE-2018-1618531İzleyin
RICOH Interactive Whiteboard D2200 V1.1 to V2.2, D5500 V1.1 to V2.2, D5510 V1.1 to V2.2, the display versions with RICOH Interactive Whitebo
YüksekCVSS 7,8İstismar yokEPSS %1ricoh · d2200 firmware9 Oca 2019
- CVE-2019-2000131İzleyin
An issue was discovered in RICOH Streamline NX Client Tool and RICOH Streamline NX PC Client that allows attackers to escalate local privile
YüksekCVSS 7,8İstismar yokEPSS %0ricoh · streamline nx client tool4 Ağu 2020
- CVE-2022-3640331İzleyin
Untrusted search path vulnerability in the installer of Device Software Manager prior to Ver.2.20.3.0 allows an attacker to gain privileges
YüksekCVSS 7,8İstismar yokEPSS %0ricoh · device software manager8 Eyl 2022
- CVE-2023-3075931İzleyin
The driver installation package created by Printer Driver Packager NX v1.0.02 to v1.1.25 fails to detect its modification and may spawn an u
YüksekCVSS 7,8İstismar yokEPSS %0ricoh · printer driver packager nx19 Haz 2023