|
223391
|
7.5 |
HIGH
Network
|
kyocera
|
ecosys_m5526cdw_firmware
|
The web application of some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) was vulnerable to path traversal, allowing an unauthenticated user to retrieve arbitrary files, or check if…
|
CWE-22
Path Traversal
|
CVE-2019-13195
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223392
|
9.8 |
CRITICAL
Network
|
xerox
|
phaser_3320_firmware
|
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Authentication Cookie of the web application that would allow an attacker to execu…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-13172
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223393
|
9.8 |
CRITICAL
Network
|
xerox
|
phaser_3320_firmware
|
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by one or more stack-based buffer overflow vulnerabilities in the Google Cloud Print implementation that would allow an unau…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13171
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223394
|
6.5 |
MEDIUM
Network
|
xerox
|
phaser_3320_firmware
|
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement any mechanism to avoid CSRF attacks. Successful exploitation of this vulnerability can lead to the takeover of a local a…
|
CWE-352
Origin Validation Error
|
CVE-2019-13170
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223395
|
9.8 |
CRITICAL
Network
|
xerox
|
phaser_3320_firmware
|
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Content-Type HTTP Header of the web application that would allow an attacker to ex…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-13169
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223396
|
9.8 |
CRITICAL
Network
|
xerox
|
phaser_3320_firmware
|
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the attributes parser of the IPP service. This would allow an unauthenticated attacker…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-13168
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223397
|
6.1 |
MEDIUM
Network
|
xerox
|
phaser_3320_firmware
|
Multiple Stored XSS vulnerabilities were found in the Xerox Web Application, used by the Phaser 3320 V53.006.16.000 and other printers. Successful exploitation of this vulnerability can lead to sessi…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13167
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223398
|
7.5 |
HIGH
Network
|
xerox
|
phaser_3320_firmware
|
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement account lockout. Local account credentials may be extracted from the device via brute force guessing attacks.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2019-13166
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223399
|
9.8 |
CRITICAL
Network
|
xerox
|
phaser_3320_firmware
|
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the request parser of the IPP service. This would allow an unauthenticated attacker to…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-13165
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223400
|
7.5 |
HIGH
Network
|
brother
|
ads-2400n_firmware ads-2800w_firmware ads-3000n_firmware ads-3600w_firmware dcp-1610w_firmware dcp-1610we_firmware dcp-1610wr_firmware dcp-1610wvb_firmware dcp-1612w_firmware<…
|
Some Brother printers (such as the HL-L8360CDW v1.20) were affected by different information disclosure vulnerabilities that provided sensitive information to an unauthenticated user who visits a spe…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-13194
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|