CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Cs31x_firmware, Cs31x, Cs41x_firmware, Cs41x, Cx310_firmware, Cx310, Ms310_firmware, Ms310, Ms312_firmware, Ms312
2022-03-04
N/A
9.8 CRITICAL
Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.
Cs31x_firmware, Cs31x, Cs41x_firmware, Cs41x, Cx310_firmware, Cx310, Ms310_firmware, Ms310, Ms312_firmware, Ms312
2022-03-17
N/A
8.8 HIGH
PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files.
The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” feature.
Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.
Cs31x_firmware, Cs31x, Cs41x_firmware, Cs41x, Cx310_firmware, Cx310, Ms310_firmware, Ms310, Ms312_firmware, Ms312
2022-03-17
N/A
9.8 CRITICAL
Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device.
500f, 500f_firmware, 7-mode_transition_tool, 8300, 8300_firmware, 8700, 8700_firmware, A220, A220_firmware, A250
2022-06-01
N/A
7 HIGH
A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object.
Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.
A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount namespace for a snap. This could allow a local attacker to gain root privileges by bind-mounting their own contents inside the snap's private mount namespace and causing snap-confine to execute arbitrary code and hence gain privilege escalation. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this binary to another location to cause snap-confine to execute other arbitrary binaries and hence gain privilege escalation. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
KNIME Server before 4.13.4 allows XSS via the old WebPortal login page.
