Show filters
133 Total Results
Displaying 31-40 of 133
Sort by:
Attacker Value
Unknown
CVE-2019-18630
Disclosure Date: March 04, 2021 (last updated February 22, 2025)
On Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200, portions of the drive containing executable code were not encrypted thus leaving it open to potential cryptographic information disclosure.
0
Attacker Value
Unknown
CVE-2019-18629
Disclosure Date: March 04, 2021 (last updated November 28, 2024)
Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200 allow an attacker to execute an unwanted binary during a exploited clone install. This requires creating a clone file and signing that file with a compromised private key.
0
Attacker Value
Unknown
CVE-2019-18628
Disclosure Date: March 04, 2021 (last updated November 28, 2024)
Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200 allow a user with administrative privileges to turn off data encryption on the device, thus leaving it open to potential cryptographic information disclosure.
0
Attacker Value
Unknown
CVE-2020-36201
Disclosure Date: January 26, 2021 (last updated February 22, 2025)
An issue was discovered in certain Xerox WorkCentre products. They do not properly encrypt passwords. This affects 3655, 3655i, 58XX, 58XXi 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices.
0
Attacker Value
Unknown
CVE-2020-26162
Disclosure Date: October 09, 2020 (last updated February 22, 2025)
Xerox WorkCentre EC7836 before 073.050.059.25300 and EC7856 before 073.020.059.25300 devices allow XSS via Description pages.
0
Attacker Value
Unknown
CVE-2016-11061
Disclosure Date: April 29, 2020 (last updated February 21, 2025)
Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410 do not properly escape parameters in the support/remoteUI/configrui.php script, which can allow an unauthenticated attacker to execute OS commands on the device.
0
Attacker Value
Unknown
CVE-2019-13167
Disclosure Date: March 13, 2020 (last updated February 21, 2025)
Multiple Stored XSS vulnerabilities were found in the Xerox Web Application, used by the Phaser 3320 V53.006.16.000 and other printers. Successful exploitation of this vulnerability can lead to session hijacking of the administrator in the web application or the execution of unwanted actions.
0
Attacker Value
Unknown
CVE-2019-13166
Disclosure Date: March 13, 2020 (last updated February 21, 2025)
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement account lockout. Local account credentials may be extracted from the device via brute force guessing attacks.
0
Attacker Value
Unknown
CVE-2019-13171
Disclosure Date: March 13, 2020 (last updated February 21, 2025)
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by one or more stack-based buffer overflow vulnerabilities in the Google Cloud Print implementation that would allow an unauthenticated attacker to execute arbitrary code on the device. This was caused by an insecure handling of the register parameters, because the size used within a memcpy() function, which copied the action value into a local variable, was not checked properly.
0
Attacker Value
Unknown
CVE-2019-13169
Disclosure Date: March 13, 2020 (last updated February 21, 2025)
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Content-Type HTTP Header of the web application that would allow an attacker to execute arbitrary code on the device.
0