Vulnerability index

Browse CVEs

62 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

C2132 Firmware HIGH 7.5
CVE-2023-40239

Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.…

Mitigation only
Fix from $1,950 2023-09-01
Cxtpc Firmware CRITICAL 9.8
CVE-2023-26063

Certain Lexmark devices through 2023-02-19 access a Resource By Using an Incompatible Type.

No fix yet
Fix from $2,300 2023-04-10
Cxtpc Firmware CRITICAL 9.8
CVE-2023-26064

Certain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.

No fix yet
Fix from $2,300 2023-04-10
Cxtpc Firmware CRITICAL 9.8
CVE-2023-26065

Certain Lexmark devices through 2023-02-19 have an Integer Overflow.

No fix yet
Fix from $2,300 2023-04-10
Cxtpc Firmware CRITICAL 9.8
CVE-2023-26066

Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.

Mitigation only
Fix from $2,300 2023-04-10
Cxtpc Firmware CRITICAL 9.8
CVE-2023-26068EPSS 12%

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).

No fix yet
Fix from $2,300 2023-04-10
Cxtpc Firmware CRITICAL 9.8
CVE-2023-26069

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4).

No fix yet
Fix from $2,300 2023-04-10
Cxtpc Firmware CRITICAL 9.8
CVE-2023-26070

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).

No fix yet
Fix from $2,300 2023-04-10
Cxtpc Firmware HIGH 8.1
CVE-2023-26067EPSS 38%

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).

No fix yet
Fix from $1,950 2023-04-10
B2236 Firmware CRITICAL 9.8
CVE-2023-23560EPSS 14%

In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.

No fix yet
Fix from $2,300 2023-01-23
B2236 Firmware HIGH 7.5
CVE-2023-22960EPSS 28%

Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.

No fix yet
Fix from $1,950 2023-01-23
B2236 Firmware HIGH 8.1
CVE-2022-29850

Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to maintain persistence across r…

Mitigation only
Fix from $1,950 2022-08-26
Lexmark Firmware HIGH 7.5
CVE-2022-24935

Lexmark products through 2022-02-10 have Incorrect Access Control.

Fix: after 2022-02-10
Fix from $1,950 2022-04-28
B2236 Firmware CRITICAL 9.8
CVE-2021-44734EPSS 6%

Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the …

No fix yet
Fix from $2,300 2022-01-20
B2236 Firmware CRITICAL 9.8
CVE-2021-44735EPSS 7%

Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.

Mitigation only
Fix from $2,300 2022-01-20
Mc3224i Firmware CRITICAL 9.8
CVE-2021-44736

The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” feature.

Mitigation only
Fix from $2,300 2022-01-20
B2236 Firmware HIGH 8.8
CVE-2021-44737

PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files.

Mitigation only
Fix from $1,950 2022-01-20
B2236 Firmware CRITICAL 9.8
CVE-2021-44738

Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.

No fix yet
Fix from $2,300 2022-01-20
G2 Driver HIGH 7.8
CVE-2021-35449

The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and be…

Fix: after 4.2.1.0
Fix from $1,950 2021-07-19
Printer Software G2 HIGH 7.8
CVE-2021-35469

The Lexmark Printer Software G2, G3 and G4 Installation Packages have a local escalation of privilege vulnerability due to a registry entry that has …

Fix: after 1.8.0.0
Fix from $1,950 2021-07-14
Cs31x Firmware MEDIUM 5.4
CVE-2020-10094

A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x before LW74.VY4.P273; CX310 befor…

Mitigation only
Fix from $1,600 2020-04-28
Cs31x Firmware MEDIUM 5.4
CVE-2020-10093

A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products.

No fix yet
Fix from $1,600 2020-04-28
6500e Firmware HIGH 7.5
CVE-2018-18894

Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server.

Mitigation only
Fix from $1,950 2020-03-10
Markvision Enterprise HIGH 8.8
CVE-2016-1487

Lexmark Markvision Enterprise before 2.3.0 misuses the Apache Commons Collections Library, leading to remote code execution because of Java deseriali…

Fix: 2.3.0+
Fix from $1,950 2020-03-09
X950 Firmware HIGH 7.5
CVE-2011-3269

Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a hidden email address in a Sca…

Mitigation only
Fix from $1,950 2020-03-09
X860 Firmware MEDIUM 5.3
CVE-2011-4538

Lexmark X, W, T, E, and C devices before 2012-02-09 allow attackers to obtain sensitive information by reading passwords within exported settings.

Mitigation only
Fix from $1,600 2020-03-09
Markvision Enterprise CRITICAL 9.8
CVE-2016-6918

Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files. (

Fix: 2.4.1+
Fix from $2,300 2020-03-09
Cs31x Firmware MEDIUM 5.4
CVE-2019-19772

Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in h…

Mitigation only
Fix from $1,600 2020-03-06
Cs31x Firmware MEDIUM 5.4
CVE-2019-19773

Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http…

Mitigation only
Fix from $1,600 2020-03-06
Cx31x Firmware MEDIUM 5.4
CVE-2019-18791

Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can…

Mitigation only
Fix from $1,600 2020-02-13