Show filters
133 Total Results
Displaying 51-60 of 133
Sort by:
Attacker Value
Unknown
CVE-2019-19832
Disclosure Date: December 18, 2019 (last updated November 27, 2024)
Xerox AltaLink C8035 printers allow CSRF. A request to add users is made in the Device User Database form field to the xerox.set URI. (The frmUserName value must have a unique name.)
0
Attacker Value
Unknown
CVE-2019-17184
Disclosure Date: October 04, 2019 (last updated November 27, 2024)
Xerox AtlaLink B8045/B8055/B8065/B8075/B8090 C8030/C8035/C8045/C8055/C8070 printers with software before 101.00x.089.22600 allow an attacker to gain privileges.
0
Attacker Value
Unknown
CVE-2019-16307
Disclosure Date: September 14, 2019 (last updated November 27, 2024)
A Reflected Cross-Site Scripting (XSS) vulnerability in the webEx module in webExMeetingLogin.jsp and deleteWebExMeetingCheck.jsp in Fuji Xerox DocuShare through 7.0.0.C1.609 allows remote attackers to inject arbitrary web script or HTML via the handle parameter (webExMeetingLogin.jsp) and meetingKey parameter (deleteWebExMeetingCheck.jsp).
0
Attacker Value
Unknown
CVE-2019-6004
Disclosure Date: September 12, 2019 (last updated November 27, 2024)
Open redirect vulnerability in ApeosWare Management Suite Ver.1.4.0.18 and earlier, and ApeosWare Management Suite 2 Ver.2.1.2.4 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
0
Attacker Value
Unknown
CVE-2018-15530
Disclosure Date: May 13, 2019 (last updated November 27, 2024)
Cross-site scripting (XSS) in the web interface of the Xerox ColorQube 8580 allows remote persistent injection of custom HTML / JavaScript code.
0
Attacker Value
Unknown
CVE-2019-10880
Disclosure Date: April 12, 2019 (last updated November 27, 2024)
Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.
0
Attacker Value
Unknown
CVE-2018-20768
Disclosure Date: February 10, 2019 (last updated November 27, 2024)
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. An attacker can execute PHP code by leveraging a writable file.
0
Attacker Value
Unknown
CVE-2018-20767
Disclosure Date: February 10, 2019 (last updated November 27, 2024)
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is authenticated remote command execution.
0
Attacker Value
Unknown
CVE-2018-20770
Disclosure Date: February 10, 2019 (last updated November 27, 2024)
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is Blind SQL Injection.
0
Attacker Value
Unknown
CVE-2018-20769
Disclosure Date: February 10, 2019 (last updated November 27, 2024)
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is a Local File Inclusion vulnerability.
0