Vulnerabilities > Lexmark > Markvision Enterprise

DATE CVE VULNERABILITY TITLE RISK
2020-03-09 CVE-2016-1487 Deserialization of Untrusted Data vulnerability in Lexmark Markvision Enterprise 2.1
Lexmark Markvision Enterprise before 2.3.0 misuses the Apache Commons Collections Library, leading to remote code execution because of Java deserialization.
network
low complexity
lexmark CWE-502
8.8
2020-03-09 CVE-2016-6918 Unrestricted Upload of File with Dangerous Type vulnerability in Lexmark Markvision Enterprise 2.1/2.3.0
Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files.
network
low complexity
lexmark CWE-434
critical
9.8
2020-01-27 CVE-2014-8742 Path Traversal vulnerability in Lexmark Markvision Enterprise
Directory traversal vulnerability in the ReportDownloadServlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
lexmark CWE-22
7.5
2020-01-27 CVE-2014-8741 Path Traversal vulnerability in Lexmark Markvision Enterprise
Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to write to arbitrary files via unspecified vectors.
network
low complexity
lexmark CWE-22
critical
9.8