Vulnerabilities (CVE)

Filtered by vendor Lexmark Subscribe
Filtered by product Xm9155
Total 9 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-40239 1 Lexmark 164 C2132, C2132 Firmware, Cs310 and 161 more 2024-11-21 N/A 7.5 HIGH
Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the vulnerability.
CVE-2023-26070 1 Lexmark 217 6500e, B2236, B2338 and 214 more 2024-11-21 N/A 9.8 CRITICAL
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).
CVE-2023-26066 1 Lexmark 217 6500e, B2236, B2338 and 214 more 2024-11-21 N/A 9.8 CRITICAL
Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.
CVE-2023-26065 1 Lexmark 217 6500e, B2236, B2338 and 214 more 2024-11-21 N/A 9.8 CRITICAL
Certain Lexmark devices through 2023-02-19 have an Integer Overflow.
CVE-2023-26064 1 Lexmark 217 6500e, B2236, B2338 and 214 more 2024-11-21 N/A 9.8 CRITICAL
Certain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.
CVE-2023-26063 1 Lexmark 217 6500e, B2236, B2338 and 214 more 2024-11-21 N/A 9.8 CRITICAL
Certain Lexmark devices through 2023-02-19 access a Resource By Using an Incompatible Type.
CVE-2021-44738 1 Lexmark 467 6500e, 6500e Firmware, B2236 and 464 more 2024-11-21 10.0 HIGH 9.8 CRITICAL
Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.
CVE-2021-44737 1 Lexmark 467 6500e, 6500e Firmware, B2236 and 464 more 2024-11-21 8.3 HIGH 8.8 HIGH
PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files.
CVE-2021-44734 1 Lexmark 467 6500e, 6500e Firmware, B2236 and 464 more 2024-11-21 10.0 HIGH 9.8 CRITICAL
Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device.