Show filters
133 Total Results
Displaying 51-60 of 133
Sort by:
Attacker Value
Unknown

CVE-2019-19832

Disclosure Date: December 18, 2019 (last updated November 27, 2024)
Xerox AltaLink C8035 printers allow CSRF. A request to add users is made in the Device User Database form field to the xerox.set URI. (The frmUserName value must have a unique name.)
Attacker Value
Unknown

CVE-2019-17184

Disclosure Date: October 04, 2019 (last updated November 27, 2024)
Xerox AtlaLink B8045/B8055/B8065/B8075/B8090 C8030/C8035/C8045/C8055/C8070 printers with software before 101.00x.089.22600 allow an attacker to gain privileges.
Attacker Value
Unknown

CVE-2019-16307

Disclosure Date: September 14, 2019 (last updated November 27, 2024)
A Reflected Cross-Site Scripting (XSS) vulnerability in the webEx module in webExMeetingLogin.jsp and deleteWebExMeetingCheck.jsp in Fuji Xerox DocuShare through 7.0.0.C1.609 allows remote attackers to inject arbitrary web script or HTML via the handle parameter (webExMeetingLogin.jsp) and meetingKey parameter (deleteWebExMeetingCheck.jsp).
Attacker Value
Unknown

CVE-2019-6004

Disclosure Date: September 12, 2019 (last updated November 27, 2024)
Open redirect vulnerability in ApeosWare Management Suite Ver.1.4.0.18 and earlier, and ApeosWare Management Suite 2 Ver.2.1.2.4 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Attacker Value
Unknown

CVE-2018-15530

Disclosure Date: May 13, 2019 (last updated November 27, 2024)
Cross-site scripting (XSS) in the web interface of the Xerox ColorQube 8580 allows remote persistent injection of custom HTML / JavaScript code.
0
Attacker Value
Unknown

CVE-2019-10880

Disclosure Date: April 12, 2019 (last updated November 27, 2024)
Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.
0
Attacker Value
Unknown

CVE-2018-20768

Disclosure Date: February 10, 2019 (last updated November 27, 2024)
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. An attacker can execute PHP code by leveraging a writable file.
0
Attacker Value
Unknown

CVE-2018-20767

Disclosure Date: February 10, 2019 (last updated November 27, 2024)
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is authenticated remote command execution.
0
Attacker Value
Unknown

CVE-2018-20770

Disclosure Date: February 10, 2019 (last updated November 27, 2024)
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is Blind SQL Injection.
0
Attacker Value
Unknown

CVE-2018-20769

Disclosure Date: February 10, 2019 (last updated November 27, 2024)
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is a Local File Inclusion vulnerability.
0