• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-13176
2019-08-28
N/A
7.5 HIGH
An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2. The Content.MainForm.wgx component is affected by XXE via a crafted XML document in POST data. There is potential to use this for SSRF (reading local files, outbound HTTP, and outbound DNS).
CVE-2019-13175
2019-07-03
N/A
6.1 MEDIUM
Read the Docs before 3.5.1 has an Open Redirect if certain user-defined redirects are used. This affects private instances of Read the Docs (in addition to the public readthedocs.org web sites).
CVE-2019-13173
2020-08-24
N/A
7.5 HIGH
fstream before 1.0.12 is vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system, and a file that matches the hardlink, will overwrite the system's file with the contents of the extracted file. The fstream.DirWriter() function is vulnerable.
CVE-2019-13172
Phaser 3320 Firmware, Xerox
Colorqube_8700_firmware, Colorqube_8700, Colorqube_8900_firmware, Colorqube_8900, Colorqube_9301_firmware, Colorqube_9301, Colorqube_9302_firmware, Colorqube_9302, Colorqube_9303_firmware, Colorqube_9303
2020-03-18
N/A
9.8 CRITICAL
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Authentication Cookie of the web application that would allow an attacker to execute arbitrary code on the device.
CVE-2019-13171
Phaser 3320 Firmware, Xerox
Colorqube_8700_firmware, Colorqube_8700, Colorqube_8900_firmware, Colorqube_8900, Colorqube_9301_firmware, Colorqube_9301, Colorqube_9302_firmware, Colorqube_9302, Colorqube_9303_firmware, Colorqube_9303
2020-03-18
N/A
9.8 CRITICAL
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by one or more stack-based buffer overflow vulnerabilities in the Google Cloud Print implementation that would allow an unauthenticated attacker to execute arbitrary code on the device. This was caused by an insecure handling of the register parameters, because the size used within a memcpy() function, which copied the action value into a local variable, was not checked properly.
CVE-2019-13170
Phaser 3320 Firmware, Xerox
Colorqube_8700_firmware, Colorqube_8700, Colorqube_8900_firmware, Colorqube_8900, Colorqube_9301_firmware, Colorqube_9301, Colorqube_9302_firmware, Colorqube_9302, Colorqube_9303_firmware, Colorqube_9303
2020-03-17
N/A
6.5 MEDIUM
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement any mechanism to avoid CSRF attacks. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device.
CVE-2019-1317
2019-10-11
N/A
7.3 HIGH
A denial of service vulnerability exists when Windows improperly handles hard links, aka 'Microsoft Windows Denial of Service Vulnerability'.
CVE-2019-13169
Phaser 3320 Firmware, Xerox
Colorqube_8700_firmware, Colorqube_8700, Colorqube_8900_firmware, Colorqube_8900, Colorqube_9301_firmware, Colorqube_9301, Colorqube_9302_firmware, Colorqube_9302, Colorqube_9303_firmware, Colorqube_9303
2020-03-18
N/A
9.8 CRITICAL
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the Content-Type HTTP Header of the web application that would allow an attacker to execute arbitrary code on the device.
CVE-2019-13168
Phaser 3320 Firmware, Xerox
Colorqube_8700_firmware, Colorqube_8700, Colorqube_8900_firmware, Colorqube_8900, Colorqube_9301_firmware, Colorqube_9301, Colorqube_9302_firmware, Colorqube_9302, Colorqube_9303_firmware, Colorqube_9303
2020-03-18
N/A
9.8 CRITICAL
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the attributes parser of the IPP service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS) and potentially execute arbitrary code on the device.
CVE-2019-13167
Phaser 3320 Firmware, Xerox
Colorqube_8700_firmware, Colorqube_8700, Colorqube_8900_firmware, Colorqube_8900, Colorqube_9301_firmware, Colorqube_9301, Colorqube_9302_firmware, Colorqube_9302, Colorqube_9303_firmware, Colorqube_9303
2020-03-18
N/A
6.1 MEDIUM
Multiple Stored XSS vulnerabilities were found in the Xerox Web Application, used by the Phaser 3320 V53.006.16.000 and other printers. Successful exploitation of this vulnerability can lead to session hijacking of the administrator in the web application or the execution of unwanted actions.
« Previous 1 … 6,315 6,316 6,317 6,318 6,319 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE