Show filters
69 Total Results
Displaying 11-20 of 69
Sort by:
Attacker Value
Unknown
CVE-2024-32151
Disclosure Date: November 26, 2024 (last updated January 05, 2025)
User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
0
Attacker Value
Unknown
CVE-2024-29978
Disclosure Date: November 26, 2024 (last updated January 05, 2025)
User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
0
Attacker Value
Unknown
CVE-2024-29146
Disclosure Date: November 26, 2024 (last updated January 05, 2025)
User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
0
Attacker Value
Unknown
CVE-2024-28955
Disclosure Date: November 26, 2024 (last updated January 05, 2025)
Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the device can examine the coredump files, and research the memory contents. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
0
Attacker Value
Unknown
CVE-2024-28038
Disclosure Date: November 26, 2024 (last updated January 05, 2025)
The web interface of the affected devices processes a cookie value improperly, leading to a stack buffer overflow. More precisely, giving too long character string to MFPSESSIONID parameter results in a stack buffer overflow. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
0
Attacker Value
Unknown
CVE-2024-48870
Disclosure Date: October 25, 2024 (last updated November 06, 2024)
Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scripting vulnerability.
If crafted input is stored by an administrative user, malicious script may be executed on the web browsers of other victim users.
0
Attacker Value
Unknown
CVE-2024-47801
Disclosure Date: October 25, 2024 (last updated November 06, 2024)
Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scripting vulnerability.
Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser.
0
Attacker Value
Unknown
CVE-2024-47549
Disclosure Date: October 25, 2024 (last updated November 06, 2024)
Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of unintended data to HTTP response headers.
Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser.
0
Attacker Value
Unknown
CVE-2024-47406
Disclosure Date: October 25, 2024 (last updated November 06, 2024)
Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulnerability.
0
Attacker Value
Unknown
CVE-2024-47005
Disclosure Date: October 25, 2024 (last updated November 06, 2024)
Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users only, but insufficiently restricted.
A non-administrative user may execute some configuration APIs.
0