Show filters
102 Total Results
Displaying 21-30 of 102
Sort by:
Attacker Value
Unknown

CVE-2024-45829

Disclosure Date: October 25, 2024 (last updated November 06, 2024)
Sharp and Toshiba Tec MFPs provide the web page to download data, where query parameters in HTTP requests are improperly processed and resulting in an Out-of-bounds Read vulnerability. Crafted HTTP requests may cause affected products crashed.
Attacker Value
Unknown

CVE-2024-43424

Disclosure Date: October 25, 2024 (last updated November 06, 2024)
Sharp and Toshiba Tec MFPs improperly process HTTP request headers, resulting in an Out-of-bounds Read vulnerability. Crafted HTTP requests may cause affected products crashed.
Attacker Value
Unknown

CVE-2024-42420

Disclosure Date: October 25, 2024 (last updated November 06, 2024)
Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword search input and improper processing of SOAP messages. Crafted HTTP requests may cause affected products crashed.
Attacker Value
Unknown

CVE-2024-3498

Disclosure Date: June 14, 2024 (last updated June 14, 2024)
Attackers can then execute malicious files by enabling certain services of the printer via the web configuration page and elevate its privileges to root. As for the affected products/models/versions, see the reference URL.
0
Attacker Value
Unknown

CVE-2024-3497

Disclosure Date: June 14, 2024 (last updated June 14, 2024)
Path traversal vulnerability in the web server of the Toshiba printer enables attacker to overwrite orginal files or add new ones to the printer. As for the affected products/models/versions, see the reference URL.
0
Attacker Value
Unknown

CVE-2024-3496

Disclosure Date: June 14, 2024 (last updated June 14, 2024)
Attackers can bypass the web login authentication process to gain access to the printer's system information and upload malicious drivers to the printer. As for the affected products/models/versions, see the reference URL.
0
Attacker Value
Unknown

CVE-2024-27180

Disclosure Date: June 14, 2024 (last updated June 14, 2024)
An attacker with admin access can install rogue applications. As for the affected products/models/versions, see the reference URL.
0
Attacker Value
Unknown

CVE-2024-27179

Disclosure Date: June 14, 2024 (last updated June 14, 2024)
Admin cookies are written in clear-text in logs. An attacker can retrieve them and bypass the authentication mechanism. As for the affected products/models/versions, see the reference URL.
0
Attacker Value
Unknown

CVE-2024-27178

Disclosure Date: June 14, 2024 (last updated June 14, 2024)
An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying file name variable. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts/products/ As for the affected products/models/versions, see the reference URL.
0
Attacker Value
Unknown

CVE-2024-27177

Disclosure Date: June 14, 2024 (last updated June 14, 2024)
An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying package name variable. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts/products/ As for the affected products/models/versions, see the reference URL.
0