Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown
CVE-2009-1656
Disclosure Date: May 16, 2009 (last updated October 04, 2023)
Xerox WorkCentre and WorkCentre Pro 232, 238, 245, 255, 265, 275; and WorkCentre 5632, 5638, 5645, 5655, 5665, 5675, 5687, 7655, 7656, and 7675 allows remote attackers to execute arbitrary commands via unknown attack vectors, aka "command injection vulnerability."
0
Attacker Value
Unknown
CVE-2006-6438
Disclosure Date: December 10, 2006 (last updated October 04, 2023)
Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 leaves sensitive user data in http.log after an Immediate Image Overwrite (IIO), which allows local users to obtain the data by reading the http.log file.
0
Attacker Value
Unknown
CVE-2006-6441
Disclosure Date: December 10, 2006 (last updated October 04, 2023)
Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows local users to bypass security controls and boot Alchemy via certain alternate boot media, as demonstrated by a USB thumb drive.
0
Attacker Value
Unknown
CVE-2006-6440
Disclosure Date: December 10, 2006 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allow remote attackers to have an unspecified impact via unspecified vectors relating to "HTTP Security issues."
0
Attacker Value
Unknown
CVE-2006-6439
Disclosure Date: December 10, 2006 (last updated October 04, 2023)
Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows remote attackers to download the audit log and obtain potentially sensitive information via unspecified vectors.
0
Attacker Value
Unknown
CVE-2006-6430
Disclosure Date: December 10, 2006 (last updated October 04, 2023)
Web services in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 do not require HTTPS, which allows remote attackers to obtain sensitive information by sniffing the unencrypted HTTP traffic.
0
Attacker Value
Unknown
CVE-2006-6436
Disclosure Date: December 10, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Network controller in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows remote attackers to inject arbitrary web script or HTML via HTTP TRACE messages.
0
Attacker Value
Unknown
CVE-2006-6434
Disclosure Date: December 10, 2006 (last updated October 04, 2023)
Unspecified vulnerability in the Web User Interface in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows remote attackers to bypass authentication controls via unknown vectors.
0
Attacker Value
Unknown
CVE-2006-5290
Disclosure Date: October 13, 2006 (last updated October 04, 2023)
The ESS/ Network Controller and MicroServer Web Server components of Xerox WorkCentre and WorkCentre Pro 232, 238, 245, 255, 265 and 275 allow remote attackers to bypass authentication and execute arbitrary code via "WebUI command injection on TCP/IP hostname."
0
Attacker Value
Unknown
CVE-2006-0825
Disclosure Date: February 21, 2006 (last updated February 22, 2025)
Multiple unspecified vulnerabilities in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allow remote attackers to bypass authentication or gain "unauthorized network access" via unknown attack vectors.
0