CVE-2023-40239
Published Sep 1, 2023Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that…
Vendor archive
66 CVEs tagged to vendor lexmark — 26 Critical, 23 High, 16 Medium, 1 Low, 0 Unrated.
Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that…
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4).
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.
Certain Lexmark devices through 2023-02-19 have an Integer Overflow.
Certain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.
Certain Lexmark devices through 2023-02-19 access a Resource By Using an Incompatible Type.
In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.
Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.
Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to maintain persistence across reboots.
Lexmark products through 2022-02-10 have Incorrect Access Control.
PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files.
The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” feature.
Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.
Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device.
Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.
The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and below are affected by a privileg…
The Lexmark Printer Software G2, G3 and G4 Installation Packages have a local escalation of privilege vulnerability due to a registry entry that has an unquoted service path.
A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x before LW74.VY4.P273; CX310 before LW74.GM2.P273; CX410 & XC213…
A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products.
Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server.
Lexmark Markvision Enterprise before 2.3.0 misuses the Apache Commons Collections Library, leading to remote code execution because of Java deserialization.
Lexmark X, W, T, E, and C devices before 2012-02-09 allow attackers to obtain sensitive information by reading passwords within exported settings.