Show filters
34 Total Results
Displaying 1-10 of 34
Sort by:
Attacker Value
Very Low

CVE-2017-16249

Disclosure Date: November 10, 2017 (last updated November 26, 2024)
The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST request can cause the server to hang until eventually replying (~300 seconds) with an HTTP 500 error. While the server is hung, print jobs over the network are blocked and the web interface is inaccessible. An attacker can continuously send this malformed request to keep the device inaccessible to legitimate traffic.
0
Attacker Value
Unknown

CVE-2024-12491

Disclosure Date: January 09, 2025 (last updated January 09, 2025)
The SimplyRETS Real Estate IDX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sr_search_form' shortcode in all versions up to, and including, 2.11.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2024-22475

Disclosure Date: March 18, 2024 (last updated April 01, 2024)
Cross-site request forgery vulnerability in multiple printers and scanners which implement Web Based Management provided by BROTHER INDUSTRIES, LTD. allows a remote unauthenticated attacker to perform unintended operations on the affected product. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
0
Attacker Value
Unknown

CVE-2024-21824

Disclosure Date: March 18, 2024 (last updated April 01, 2024)
Improper authentication vulnerability in exists in multiple printers and scanners which implement Web Based Management provided by BROTHER INDUSTRIES, LTD. If this vulnerability is exploited, a network-adjacent user who can access the product may impersonate an administrative user. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
0
Attacker Value
Unknown

CVE-2023-51654

Disclosure Date: December 26, 2023 (last updated January 05, 2024)
Improper link resolution before file access ('Link Following') issue exists in iPrint&Scan Desktop for Windows versions 11.0.0 and earlier. A symlink attack by a malicious user may cause a Denial-of-service (DoS) condition on the PC.
Attacker Value
Unknown

CVE-2023-29984

Disclosure Date: July 11, 2023 (last updated October 08, 2023)
Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As for the affected products/models/versions, see the detailed information provided by each vendor.
Attacker Value
Unknown

CVE-2023-28369

Disclosure Date: May 18, 2023 (last updated October 08, 2023)
Brother iPrint&Scan V6.11.2 and earlier contains an improper access control vulnerability. This vulnerability may be exploited by the other app installed on the victim user's Android device, which may lead to displaying the settings and/or log information of the affected app as a print preview.
Attacker Value
Unknown

CVE-2019-13193

Disclosure Date: March 13, 2020 (last updated February 21, 2025)
Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a stack buffer overflow vulnerability as the web server did not parse the cookie value properly. This would allow an attacker to execute arbitrary code on the device.
Attacker Value
Unknown

CVE-2019-13192

Disclosure Date: March 13, 2020 (last updated February 21, 2025)
Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a heap buffer overflow vulnerability as the IPP service did not parse attribute names properly. This would allow an attacker to execute arbitrary code on the device.
Attacker Value
Unknown

CVE-2019-13194

Disclosure Date: March 13, 2020 (last updated February 21, 2025)
Some Brother printers (such as the HL-L8360CDW v1.20) were affected by different information disclosure vulnerabilities that provided sensitive information to an unauthenticated user who visits a specific URL.