Vulnerabilities > Lexmark > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-09-01 | CVE-2023-40239 | XXE vulnerability in Lexmark products Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. | 7.5 |
2023-04-10 | CVE-2023-26067 | Improper Input Validation vulnerability in Lexmark products Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4). | 8.1 |
2023-01-23 | CVE-2023-22960 | Improper Restriction of Excessive Authentication Attempts vulnerability in Lexmark products Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency. | 7.5 |
2022-08-26 | CVE-2022-29850 | Exposure of Resource to Wrong Sphere vulnerability in Lexmark products Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to maintain persistence across reboots. | 8.1 |
2022-04-28 | CVE-2022-24935 | Missing Authentication for Critical Function vulnerability in Lexmark Firmware Lexmark products through 2022-02-10 have Incorrect Access Control. | 7.5 |
2022-01-20 | CVE-2021-44737 | Path Traversal vulnerability in Lexmark products PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files. | 8.8 |
2021-07-19 | CVE-2021-35449 | Incorrect Permission Assignment for Critical Resource vulnerability in Lexmark products The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and below are affected by a privilege escalation vulnerability. | 7.8 |
2021-07-14 | CVE-2021-35469 | Unquoted Search Path or Element vulnerability in Lexmark products The Lexmark Printer Software G2, G3 and G4 Installation Packages have a local escalation of privilege vulnerability due to a registry entry that has an unquoted service path. | 7.8 |
2020-03-10 | CVE-2018-18894 | Path Traversal vulnerability in Lexmark products Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server. | 7.5 |
2020-03-09 | CVE-2016-1487 | Deserialization of Untrusted Data vulnerability in Lexmark Markvision Enterprise 2.1 Lexmark Markvision Enterprise before 2.3.0 misuses the Apache Commons Collections Library, leading to remote code execution because of Java deserialization. | 8.8 |