Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.…
Certain Lexmark devices through 2023-02-19 access a Resource By Using an Incompatible Type.
Certain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.
Certain Lexmark devices through 2023-02-19 have an Integer Overflow.
Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4).
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.
Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.
Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to maintain persistence across r…
Lexmark products through 2022-02-10 have Incorrect Access Control.
Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the …
Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.
The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” feature.
PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files.
Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.
The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and be…
The Lexmark Printer Software G2, G3 and G4 Installation Packages have a local escalation of privilege vulnerability due to a registry entry that has …
A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x before LW74.VY4.P273; CX310 befor…
A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products.
Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server.
Lexmark Markvision Enterprise before 2.3.0 misuses the Apache Commons Collections Library, leading to remote code execution because of Java deseriali…
Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a hidden email address in a Sca…
Lexmark X, W, T, E, and C devices before 2012-02-09 allow attackers to obtain sensitive information by reading passwords within exported settings.
Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files. (
Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in h…
Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http…
Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can…