Vulnerability index

Browse CVEs

22 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Mf644cdw Firmware HIGH 8.8
CVE-2022-43608

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.03 printers.…

Mitigation only
Fix from $1,950 2023-03-29
D1620 Firmware CRITICAL 9.8
CVE-2022-24673

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers. Authentic…

Mitigation only
Fix from $2,300 2023-03-28
D1620 Firmware HIGH 8.8
CVE-2022-24672

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers.…

Mitigation only
Fix from $1,950 2023-03-28
D1620 Firmware HIGH 8.8
CVE-2022-24674

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers.…

Mitigation only
Fix from $1,950 2023-03-28
Lbp223dw Firmware HIGH 7.5
CVE-2021-43471

In Canon LBP223 printers, the System Manager Mode login does not require an account password or PIN. An attacker can remotely shut down the device af…

No fix yet
Fix from $1,950 2021-12-06
Unclassified HIGH 7.5
CVE-2021-38154

Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, a…

No fix yet
Fix from $1,950 2021-08-29
Oce Print Exec Workgroup MEDIUM 6.1
CVE-2021-39368

Canon Oce Print Exec Workgroup 1.3.2 allows XSS via the lang parameter.

No fix yet
Fix from $1,600 2021-08-23
Oce Print Exec Workgroup MEDIUM 5.3
CVE-2021-39367

Canon Oce Print Exec Workgroup 1.3.2 allows Host header injection.

No fix yet
Fix from $1,600 2021-08-23
Mf237w Firmware HIGH 7.5
CVE-2020-16849

An issue was discovered on Canon MF237w 06.07 devices. An "Improper Handling of Length Parameter Inconsistency" issue in the IPv4/ICMPv4 component, w…

Mitigation only
Fix from $1,950 2020-11-30
Oce Colorwave 3500 Firmware CRITICAL 9.8
CVE-2020-26508

The WebTools component on Canon Oce ColorWave 3500 5.1.1.0 devices allows attackers to retrieve stored SMB credentials via the export feature, even t…

Mitigation only
Fix from $2,300 2020-11-16
Oce Colorwave 500 Firmware HIGH 7.5
CVE-2020-10669

The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to authentication bypass on the page /home.jsp. An unauthent…

No fix yet
Fix from $1,950 2020-03-19
Print MEDIUM 5.5
CVE-2019-14339EPSS 5%

The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly restrict canon.ij.printer.capabi…

No fix yet
Fix from $1,600 2019-09-05
Efi Printme MEDIUM 6.1
CVE-2018-12111

Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitrary web script or HTML via the…

No fix yet
Fix from $1,600 2018-06-11
Lbp7110cw Firmware CRITICAL 9.8
CVE-2018-12048EPSS 5%

A remote attacker can bypass the Management Mode on the Canon LBP7110Cw web interface without a PIN for /checkLogin.cgi via vectors involving /portal…

No fix yet
Fix from $2,300 2018-06-08
Lbp6030w Firmware CRITICAL 9.8
CVE-2018-12049EPSS 5%

A remote attacker can bypass the System Manager Mode on the Canon LBP6030w web interface without a PIN for /checkLogin.cgi via vectors involving /por…

No fix yet
Fix from $2,300 2018-06-08
Mf210 Firmware CRITICAL 9.8
CVE-2018-11711EPSS 5%

A remote attacker can bypass the System Manager Mode on the Canon MF210 and MF220 web interface without knowing the PIN for /login.html via vectors i…

No fix yet
Fix from $2,300 2018-06-04
Lbp3370 Firmware CRITICAL 9.8
CVE-2018-11692

An issue was discovered on Canon LBP6650, LBP3370, LBP3460, and LBP7750C devices. It is possible to bypass the Administrator Mode authentication for …

No fix yet
Fix from $2,300 2018-06-04
Pixma Mg7500 Series Inkjet Printer MEDIUM 6.8
CVE-2015-5631

Cross-site request forgery (CSRF) vulnerability in the Remote UI on Canon PIXMA MG7500 printers allows remote attackers to hijack the authentication …

Mitigation only
Fix from $1,600 2015-09-11
Mg3100 Printer HIGH 7.5
CVE-2013-4613

The default configuration of the administrative interface on the Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers …

Mitigation only
Fix from $1,950 2013-06-21
Mg3100 Printer MEDIUM 5.0
CVE-2013-4615EPSS 16%

The Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers allow remote attackers to cause a denial of service (device h…

Mitigation only
Fix from $1,600 2013-06-21
I Sensys MEDIUM 6.4
CVE-2008-0303

The FTP print feature in multiple Canon printers, including imageRUNNER and imagePRESS, allow remote attackers to use the server as an inadvertent pr…

Mitigation only
Fix from $1,600 2008-02-29
Imagerunner 5000i HIGH 7.5
CVE-2004-2166

The print-from-email feature in the Canon ImageRUNNER (iR) 5000i and C3200 digital printer, when not using IP address range filtering, allows remote …

Mitigation only
Fix from $1,950 2004-12-31