Show filters
59 Total Results
Displaying 11-20 of 59
Sort by:
Attacker Value
Unknown
CVE-2024-29978
Disclosure Date: November 26, 2024 (last updated January 05, 2025)
User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
0
Attacker Value
Unknown
CVE-2024-29146
Disclosure Date: November 26, 2024 (last updated January 05, 2025)
User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
0
Attacker Value
Unknown
CVE-2024-28955
Disclosure Date: November 26, 2024 (last updated January 05, 2025)
Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the device can examine the coredump files, and research the memory contents. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
0
Attacker Value
Unknown
CVE-2024-28038
Disclosure Date: November 26, 2024 (last updated January 05, 2025)
The web interface of the affected devices processes a cookie value improperly, leading to a stack buffer overflow. More precisely, giving too long character string to MFPSESSIONID parameter results in a stack buffer overflow. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
0
Attacker Value
Unknown
CVE-2024-3498
Disclosure Date: June 14, 2024 (last updated June 14, 2024)
Attackers can then execute malicious files by enabling certain services of the printer via the web configuration page and elevate its privileges to root. As for the affected products/models/versions, see the reference URL.
0
Attacker Value
Unknown
CVE-2024-3497
Disclosure Date: June 14, 2024 (last updated June 14, 2024)
Path traversal vulnerability in the web server of the Toshiba printer enables attacker to overwrite orginal files or add new ones to the printer. As for the affected products/models/versions, see the reference URL.
0
Attacker Value
Unknown
CVE-2024-3496
Disclosure Date: June 14, 2024 (last updated June 14, 2024)
Attackers can bypass the web login authentication process to gain access to the printer's system information and upload malicious drivers to the printer. As for the affected products/models/versions, see the reference URL.
0
Attacker Value
Unknown
CVE-2024-27180
Disclosure Date: June 14, 2024 (last updated June 14, 2024)
An attacker with admin access can install rogue applications. As for the affected products/models/versions, see the reference URL.
0
Attacker Value
Unknown
CVE-2024-27179
Disclosure Date: June 14, 2024 (last updated June 14, 2024)
Admin cookies are written in clear-text in logs. An attacker can retrieve them and bypass the authentication mechanism. As for the affected products/models/versions, see the reference URL.
0
Attacker Value
Unknown
CVE-2024-27178
Disclosure Date: June 14, 2024 (last updated June 14, 2024)
An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying file name variable. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point.
https://www.toshibatec.com/contacts/products/
As for the affected products/models/versions, see the reference URL.
0