Vulnerability index

Browse CVEs

105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Altalink B8045 Firmware HIGH 8.1
CVE-2019-18629

Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software releases before 101.00x.099.28200…

Fix: 101.001.099.28200 / 101.002.099.28200+
Fix from $1,950 2021-03-04
Workcentre 3655 Firmware HIGH 7.5
CVE-2020-36201

An issue was discovered in certain Xerox WorkCentre products. They do not properly encrypt passwords. This affects 3655, 3655i, 58XX, 58XXi 59XX, 59X…

Fix: 075.060.000.12010 / 075.091.010.12010+
Fix from $1,950 2021-01-26
Workcentre Ec7836 Firmware MEDIUM 6.1
CVE-2020-26162

Xerox WorkCentre EC7836 before 073.050.059.25300 and EC7856 before 073.020.059.25300 devices allow XSS via Description pages.

Fix: 073.020.059.25300 / 073.050.059.25300+
Fix from $1,600 2020-10-09
Workcentre 3655 Firmware CRITICAL 9.8
CVE-2016-11061

Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410 do no…

Fix: 073.060.086.15410 / 073.190.086.15410+
Fix from $2,300 2020-04-29
Phaser 3320 Firmware CRITICAL 9.8
CVE-2019-13171

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by one or more stack-based buffer overflow vulnerabilities in the Google C…

Mitigation only
Fix from $2,300 2020-03-13
Phaser 3320 Firmware CRITICAL 9.8
CVE-2019-13172

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Authentication Cookie of the web…

Mitigation only
Fix from $2,300 2020-03-13
Phaser 3320 Firmware CRITICAL 9.8
CVE-2019-13165

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the request parser of the IPP servic…

Mitigation only
Fix from $2,300 2020-03-13
Phaser 3320 Firmware CRITICAL 9.8
CVE-2019-13168

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the attributes parser of the IPP ser…

Mitigation only
Fix from $2,300 2020-03-13
Phaser 3320 Firmware CRITICAL 9.8
CVE-2019-13169

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Content-Type HTTP Header of the …

Mitigation only
Fix from $2,300 2020-03-13
Phaser 3320 Firmware HIGH 7.5
CVE-2019-13166

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement account lockout. Local account credentials may be extracted from the d…

Mitigation only
Fix from $1,950 2020-03-13
Phaser 3320 Firmware MEDIUM 6.5
CVE-2019-13170

Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement any mechanism to avoid CSRF attacks. Successful exploitation of this v…

Mitigation only
Fix from $1,600 2020-03-13
Phaser 3320 Firmware MEDIUM 6.1
CVE-2019-13167

Multiple Stored XSS vulnerabilities were found in the Xerox Web Application, used by the Phaser 3320 V53.006.16.000 and other printers. Successful ex…

Mitigation only
Fix from $1,600 2020-03-13
Workcentre 3655 Firmware HIGH 8.8
CVE-2020-9330

Certain Xerox WorkCentre printers before 073.xxx.000.02300 do not require the user to reenter or validate LDAP bind credentials when changing the LDA…

Fix: 073.060.000.02300 / 073.091.000.02300+
Fix from $1,950 2020-02-21
Colorqube 9201 Firmware CRITICAL 9.8
CVE-2013-6362

Xerox ColorCube and WorkCenter devices in 2013 had hardcoded FTP and shell user accounts.

No fix yet
Fix from $2,300 2020-02-13
Altalink C8035 Firmware HIGH 8.8
CVE-2019-19832

Xerox AltaLink C8035 printers allow CSRF. A request to add users is made in the Device User Database form field to the xerox.set URI. (The frmUserNam…

No fix yet
Fix from $1,950 2019-12-18
Atlalink Firmware CRITICAL 9.8
CVE-2019-17184

Xerox AtlaLink B8045/B8055/B8065/B8075/B8090 C8030/C8035/C8045/C8055/C8070 printers with software before 101.00x.089.22600 allow an attacker to gain …

No fix yet
Fix from $2,300 2019-10-04
Colorqube 8580 Firmware MEDIUM 6.1
CVE-2018-15530

Cross-site scripting (XSS) in the web interface of the Xerox ColorQube 8580 allows remote persistent injection of custom HTML / JavaScript code.

No fix yet
Fix from $1,600 2019-05-13
Colorqube 8700 Firmware CRITICAL 9.8
CVE-2019-10880EPSS 8%

Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" req…

Fix: 072.161.009.07200 / 072.180.009.07200+
Fix from $2,300 2019-04-12
Workcentre 3655i Firmware CRITICAL 9.8
CVE-2018-20768

An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC…

Fix: 073.060.048.15000 / 073.190.048.15000+
Fix from $2,300 2019-02-10
Workcentre 3655i Firmware CRITICAL 9.8
CVE-2018-20770

An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC…

Fix: 073.060.048.15000 / 073.190.048.15000+
Fix from $2,300 2019-02-10
Workcentre 3655i Firmware CRITICAL 9.8
CVE-2018-20771

An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC…

Fix: 073.060.048.15000 / 073.190.048.15000+
Fix from $2,300 2019-02-10
Workcentre 3655i Firmware HIGH 8.8
CVE-2018-20767

An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC…

Fix: 073.060.048.15000 / 073.190.048.15000+
Fix from $1,950 2019-02-10
Workcentre 3655i Firmware HIGH 7.5
CVE-2018-20769

An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC…

Fix: 073.060.048.15000 / 073.190.048.15000+
Fix from $1,950 2019-02-10
Altalink C8030 Firmware CRITICAL 9.8
CVE-2018-17172

The web application on Xerox AltaLink B80xx before 100.008.028.05200, C8030/C8035 before 100.001.028.05200, C8045/C8055 before 100.002.028.05200, and…

Fix: 100.001.028.05200 / 100.002.028.05200+
Fix from $2,300 2019-01-03
Docushare MEDIUM 6.5
CVE-2014-3138

SQL injection vulnerability in Xerox DocuShare before 6.53 Patch 6 Hotfix 2, 6.6.1 Update 1 before Hotfix 24, and 6.6.1 Update 2 before Hotfix 3 allo…

No fix yet
Fix from $1,600 2014-05-02
Freeflow Print Server MEDIUM 6.0
CVE-2013-0415

Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors rela…

Patch available
Fix from $1,600 2013-01-17
Workcentre 5632 MEDIUM 5.0
CVE-2010-0548

Multiple unspecified vulnerabilities in the Network Controller and Web Server in Xerox WorkCentre 5632, 5638, 5645, 5655, 5665, 5675, and 5687 allow …

Patch available
Fix from $1,600 2010-02-04
Workcentre 6400 Net Controller MEDIUM 5.0
CVE-2010-0549

Unspecified vulnerability in the Network Controller in Xerox WorkCentre 6400 System Software 060.070.109.11407 through 060.070.109.29510, and Net Con…

Patch available
Fix from $1,600 2010-02-04
Fiery Webtools HIGH 7.5
CVE-2009-3913

SQL injection vulnerability in summary.php in Xerox Fiery Webtools allows remote attackers to execute arbitrary SQL commands via the select parameter.

Mitigation only
Fix from $1,950 2009-11-09
Workcentre HIGH 10.0
CVE-2009-1656

Xerox WorkCentre and WorkCentre Pro 232, 238, 245, 255, 265, 275; and WorkCentre 5632, 5638, 5645, 5655, 5665, 5675, 5687, 7655, 7656, and 7675 allow…

Patch available
Fix from $1,950 2009-05-16