Vulnerabilities > Canon > High

DATE CVE VULNERABILITY TITLE RISK
2013-06-21 CVE-2013-4613 Permissions, Privileges, and Access Controls vulnerability in Canon products
The default configuration of the administrative interface on the Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers does not require authentication, which allows remote attackers to modify the configuration by visiting the Advanced page.
network
low complexity
canon CWE-264
7.5
2006-04-11 CVE-2006-1188 Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads to memory corruption.
network
low complexity
microsoft canon
7.5
2006-04-11 CVE-2006-1185 Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption.
network
low complexity
microsoft canon
7.5
2005-12-31 CVE-2005-4827 Internet Explorer 6.0, and possibly other versions, allows remote attackers to bypass the same origin security policy and make requests outside of the intended domain by calling open on an XMLHttpRequest object (Microsoft.XMLHTTP) and using tab, newline, and carriage return characters within the first argument (method name), which is supported by some proxy servers that convert tabs to spaces.
network
low complexity
microsoft canon
7.5
2004-12-31 CVE-2004-2166 Unspecified vulnerability in Canon Imagerunner 5000I and Imagerunner C3200
The print-from-email feature in the Canon ImageRUNNER (iR) 5000i and C3200 digital printer, when not using IP address range filtering, allows remote attackers to print arbitrary text without authentication via a text/plain email to TCP port 25.
network
low complexity
canon
7.5