Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-02-06 CVE-2023-6229 Out-of-bounds Write vulnerability in Canon products
Buffer overflow in CPCA PDL Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan.
network
low complexity
canon CWE-787
critical
9.8
2024-02-06 CVE-2023-6230 Out-of-bounds Write vulnerability in Canon products
Buffer overflow in the Address Book password process in authentication of Mobile Device Function of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan.
network
low complexity
canon CWE-787
critical
9.8
2024-02-06 CVE-2023-6231 Out-of-bounds Write vulnerability in Canon products
Buffer overflow in WSD probe request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan.
network
low complexity
canon CWE-787
critical
9.8
2024-02-06 CVE-2023-6232 Out-of-bounds Write vulnerability in Canon products
Buffer overflow in the Address Book username process in authentication of Mobile Device Function of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan.
network
low complexity
canon CWE-787
critical
9.8
2024-02-06 CVE-2023-6233 Out-of-bounds Write vulnerability in Canon products
Buffer overflow in SLP attribute request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan.
network
low complexity
canon CWE-787
critical
9.8
2024-02-06 CVE-2023-6234 Out-of-bounds Write vulnerability in Canon products
Buffer overflow in CPCA Color LUT Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan.
network
low complexity
canon CWE-787
critical
9.8
2024-02-06 CVE-2024-0244 Out-of-bounds Write vulnerability in Canon products
Buffer overflow in CPCA PCFAX number process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF750C Series firmware v03.07 and earlier sold in Japan.
network
low complexity
canon CWE-787
critical
9.8
2024-02-06 CVE-2024-24112 SQL Injection vulnerability in Exrick Xmall 1.1
xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.
network
low complexity
exrick CWE-89
critical
9.8
2024-02-06 CVE-2024-24398 Path Traversal vulnerability in Stimulsoft Dashboards.PHP
Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function.
network
low complexity
stimulsoft CWE-22
critical
9.8
2024-02-05 CVE-2024-0964 Path Traversal vulnerability in Gradio Project Gradio
A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API request.
network
low complexity
gradio-project CWE-22
critical
9.4