Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
xerox vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2019-13167
Multiple Stored XSS vulnerabilities were found in the Xerox Web Application, used by the Phaser 3320 V53.006.16.000 and other printers. Successful exploitation of this vulnerability can lead to session hijacking of the administrator in the web application or the execution of unwa...
Xerox Phaser 3320 Firmware V53.006.16.000
10
CVSSv2
CVE-2019-13169
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Content-Type HTTP Header of the web application that would allow an malicious user to execute arbitrary code on the device.
Xerox Phaser 3320 Firmware V53.006.16.000
4.3
CVSSv2
CVE-2019-13170
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement any mechanism to avoid CSRF attacks. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device.
Xerox Phaser 3320 Firmware V53.006.16.000
10
CVSSv2
CVE-2019-13172
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Authentication Cookie of the web application that would allow an malicious user to execute arbitrary code on the device.
Xerox Phaser 3320 Firmware V53.006.16.000
7.5
CVSSv2
CVE-2009-3913
SQL injection vulnerability in summary.php in Xerox Fiery Webtools allows remote malicious users to execute arbitrary SQL commands via the select parameter.
Xerox Fiery Webtools
1 EDB exploit
NA
CVE-2022-45897
On Xerox WorkCentre 3550 25.003.03.000 devices, an authenticated attacker can view the SMB server settings and can obtain the stored cleartext credentials associated with those settings.
Xerox Workcentre 3550 Firmware 25.003.03.000
6.5
CVSSv2
CVE-2008-3122
Multiple SQL injection vulnerabilities in Xerox CentreWare Web (CWW) prior to 4.6.46 allow remote authenticated users to execute arbitrary SQL commands via the unspecified vectors.
Xerox Centreware Web
7.5
CVSSv2
CVE-2021-37354
Xerox Phaser 4622 v35.013.01.000 exists to contain a buffer overflow in the function sub_3226AC via the TIMEZONE variable. This vulnerability allows malicious users to cause a Denial of Service (DoS) via crafted overflow data.
Xerox Phaser 4622 Firmware 35.013.01.000
5
CVSSv2
CVE-1999-1343
HTTP server for Xerox DocuColor 4 LP allows remote malicious users to cause a denial of service (hang) via a long URL that contains a large number of . characters.
Xerox Docucolor 4lp
5
CVSSv2
CVE-2022-23320
XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and exfiltrate sensitive information from the database.
Xerox Xmpie Ustore 12.3.7244.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-22460
CVE-2024-4646
CVE-2024-29212
IMAP
CVE-2023-36672
CVE-2024-34547
command injection
CVE-2024-4651
stored XSS
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
6
7
8
9
10
NEXT »