|
223581
|
6.1 |
MEDIUM
Network
|
xerox
|
phaser_3320_firmware
|
Multiple Stored XSS vulnerabilities were found in the Xerox Web Application, used by the Phaser 3320 V53.006.16.000 and other printers. Successful exploitation of this vulnerability can lead to sessi…
|
CWE-79
Cross-site Scripting
|
CVE-2019-13167
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223582
|
7.5 |
HIGH
Network
|
xerox
|
phaser_3320_firmware
|
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement account lockout. Local account credentials may be extracted from the device via brute force guessing attacks.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2019-13166
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223583
|
9.8 |
CRITICAL
Network
|
xerox
|
phaser_3320_firmware
|
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the request parser of the IPP service. This would allow an unauthenticated attacker to…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-13165
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223584
|
7.5 |
HIGH
Network
|
brother
|
ads-2400n_firmware ads-2800w_firmware ads-3000n_firmware ads-3600w_firmware dcp-1610w_firmware dcp-1610we_firmware dcp-1610wr_firmware dcp-1610wvb_firmware dcp-1612w_firmware<…
|
Some Brother printers (such as the HL-L8360CDW v1.20) were affected by different information disclosure vulnerabilities that provided sensitive information to an unauthenticated user who visits a spe…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-13194
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223585
|
8.8 |
HIGH
Network
|
brother
|
ads-2400n_firmware ads-2800w_firmware ads-3000n_firmware ads-3600w_firmware dcp-1610w_firmware dcp-1610we_firmware dcp-1610wr_firmware dcp-1610wvb_firmware dcp-1612w_firmware<…
|
Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a stack buffer overflow vulnerability as the web server did not parse the cookie value properly. This would allow an attacker to…
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13193
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223586
|
9.8 |
CRITICAL
Network
|
brother
|
ads-2400n_firmware ads-2800w_firmware ads-3000n_firmware ads-3600w_firmware dcp-1610w_firmware dcp-1610we_firmware dcp-1610wr_firmware dcp-1610wvb_firmware dcp-1612w_firmware<…
|
Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a heap buffer overflow vulnerability as the IPP service did not parse attribute names properly. This would allow an attacker to …
|
CWE-787
Out-of-bounds Write
|
CVE-2019-13192
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223587
|
8.8 |
HIGH
Network
|
netgear
|
cg3700b_firmware
|
The Voo branded NETGEAR CG3700b custom firmware V2.02.03 allows CSRF against all /goform/ URIs. An attacker can modify all settings including WEP/WPA/WPA2 keys, restore the router to factory settings…
|
CWE-352
Origin Validation Error
|
CVE-2019-13395
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223588
|
9.8 |
CRITICAL
Network
|
netgear
|
cg3700b_firmware
|
The Voo branded NETGEAR CG3700b custom firmware V2.02.03 uses HTTP Basic Authentication over cleartext HTTP.
|
CWE-319 CWE-522
Cleartext Transmission of Sensitive Information Insufficiently Protected Credentials
|
CVE-2019-13394
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223589
|
7.5 |
HIGH
Network
|
netgear
|
cg3700b_firmware
|
The Voo branded NETGEAR CG3700b custom firmware V2.02.03 uses the same default 8 character passphrase for the administrative console and the WPA2 pre-shared key. Either an attack against HTTP Basic A…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2019-13393
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223590
|
8.8 |
HIGH
Network
|
kyocera
|
ecosys_m5526cdw_firmware
|
Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in multiple parameters of the Document Boxes functionality of the web application…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-13206
|
2024-11-21 13:24 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|