VYPR

Vendor CVEs

Lexmark

All CVEs

88 total · sorted by risk
  • CVE-2014-8741CriJan 27, 2020
    risk 0.73cvss 9.8epss 0.77

    Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to write to arbitrary files via unspecified vectors.

  • CVE-2023-26068CriApr 10, 2023
    risk 0.68cvss 9.8epss 0.12

    Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).

  • CVE-2023-23560CriJan 23, 2023
    risk 0.65cvss 9.8epss 0.14

    In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.

  • CVE-2023-26070CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).

  • CVE-2023-26069CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4).

  • CVE-2023-26066CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.

  • CVE-2023-26065CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain Lexmark devices through 2023-02-19 have an Integer Overflow.

  • CVE-2023-26064CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.

  • CVE-2023-26063CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain Lexmark devices through 2023-02-19 access a Resource By Using an Incompatible Type.

  • CVE-2021-44736CriJan 20, 2022
    risk 0.64cvss 9.8epss 0.02

    The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” feature.

  • CVE-2021-44735CriJan 20, 2022
    risk 0.64cvss 9.8epss 0.07

    Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.

  • CVE-2021-44734CriJan 20, 2022
    risk 0.64cvss 9.8epss 0.06

    Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device.

  • CVE-2021-44738CriJan 20, 2022
    risk 0.64cvss 9.8epss 0.03

    Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.

  • CVE-2016-6918CriMar 9, 2020
    risk 0.64cvss 9.8epss 0.02

    Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files. (

  • CVE-2019-9933CriAug 28, 2019
    risk 0.64cvss 9.8epss 0.02

    Various Lexmark products have a Buffer Overflow (issue 3 of 3).

  • CVE-2019-9932CriAug 28, 2019
    risk 0.64cvss 9.8epss 0.02

    Various Lexmark products have a Buffer Overflow (issue 2 of 3).

  • CVE-2019-9930CriAug 28, 2019
    risk 0.64cvss 9.8epss 0.02

    Various Lexmark products have an Integer Overflow.

  • CVE-2018-15519CriJun 28, 2019
    risk 0.64cvss 9.8epss 0.01

    Various Lexmark devices have a Buffer Overflow (issue 1 of 2).

  • CVE-2018-15520CriJun 28, 2019
    risk 0.64cvss 9.8epss 0.01

    Various Lexmark devices have a Buffer Overflow (issue 2 of 2).

  • CVE-2017-13771CriSep 7, 2017
    risk 0.64cvss 9.8epss 0.03

    Lexmark Scan To Network (SNF) 3.2.9 and earlier stores network configuration credentials in plaintext and transmits them in requests, which allows remote attackers to obtain sensitive information via requests to (1) cgi-bin/direct/printer/prtappauth/apps/snfDestServlet or (2)…

  • CVE-2016-4336CriJan 6, 2017
    risk 0.64cvss 9.8epss 0.04

    An exploitable out-of-bounds write exists in the Bzip2 parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted Bzip2 document can lead to a stack-based buffer overflow causing an out-of-bounds write which under the right circumstance could…

  • CVE-2016-1896CriJan 27, 2016
    risk 0.64cvss 9.8epss 0.03

    Race condition in the initialization process on Lexmark printers with firmware ATL before ATL.02.049, CB before CB.02.049, PP before PP.02.049, and YK before YK.02.049 allows remote attackers to bypass authentication by leveraging incorrect detection of the security-jumper…

  • CVE-2025-65078CriFeb 3, 2026
    risk 0.60cvss epss 0.01

    An untrusted search path vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code.

  • CVE-2025-1126CriFeb 11, 2025
    risk 0.60cvss 9.3epss 0.00

    A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the Lexmark Print Management Client.

  • CVE-2020-35546CriFeb 19, 2025
    risk 0.59cvss 9.1epss 0.00

    Lexmark MX6500 LW75.JD.P296 and previous devices have Incorrect Access Control via the access control settings.

  • CVE-2023-50737CriFeb 28, 2024
    risk 0.59cvss 9.1epss 0.01

    The SE menu contains information used by Lexmark to diagnose device errors. A vulnerability in one of the SE menu routines can be leveraged by an attacker to execute arbitrary code.

  • CVE-2023-50736CriFeb 28, 2024
    risk 0.59cvss 9.0epss 0.01

    A memory corruption vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.

  • CVE-2023-50735CriFeb 28, 2024
    risk 0.59cvss 9.0epss 0.01

    A heap corruption vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.

  • CVE-2023-50734CriFeb 28, 2024
    risk 0.59cvss 9.0epss 0.01

    A buffer overflow vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.

  • CVE-2019-10058CriAug 28, 2019
    risk 0.59cvss 9.1epss 0.01

    Various Lexmark products have Incorrect Access Control.

  • CVE-2025-65077HigFeb 3, 2026
    risk 0.57cvss epss 0.01

    A relative path traversal vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user.

  • CVE-2023-50739HigJan 18, 2025
    risk 0.57cvss 8.8epss 0.01

    A buffer overflow vulnerability has been identified in the Internet Printing Protocol (IPP) in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.

  • CVE-2021-44737HigJan 20, 2022
    risk 0.57cvss 8.8epss 0.01

    PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files.

  • CVE-2016-1487HigMar 9, 2020
    risk 0.57cvss 8.8epss 0.03

    Lexmark Markvision Enterprise before 2.3.0 misuses the Apache Commons Collections Library, leading to remote code execution because of Java deserialization.

  • CVE-2017-2821HigSep 5, 2017
    risk 0.57cvss 8.8epss 0.02

    An exploitable use-after-free exists in the PDF parsing functionality of Lexmark Perspective Document Filters 11.3.0.2400 and 11.4.0.2452. A crafted PDF document can lead to a use-after-free resulting in direct code execution.

  • CVE-2023-50733HigJan 21, 2025
    risk 0.56cvss 8.6epss 0.00

    A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Web Services feature of newer Lexmark devices.

  • CVE-2023-26067HigApr 10, 2023
    risk 0.56cvss 8.1epss 0.38

    Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).

  • CVE-2025-4046HigAug 19, 2025
    risk 0.55cvss 8.5epss 0.00

    A missing authorization vulnerability in Lexmark Cloud Services badge management allows attacker to reassign badges within their organization

  • CVE-2016-4335HigJan 6, 2017
    risk 0.55cvss 8.4epss 0.04

    An exploitable buffer overflow exists in the XLS parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted XLS document can lead to a stack based buffer overflow resulting in remote code execution.

  • CVE-2021-35449HigJul 19, 2021
    risk 0.54cvss 7.8epss 0.01

    The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and below are affected by a privilege escalation vulnerability. A standard low priviliged user can use the driver to execute a DLL of…

  • CVE-2025-4044HigAug 19, 2025
    risk 0.53cvss 8.2epss 0.00

    Improper Restriction of XML External Entity Reference in various Lexmark printer drivers for Windows allows attacker to disclose sensitive information to an arbitrary URL.

  • CVE-2020-10095HigFeb 19, 2025
    risk 0.53cvss 8.1epss 0.00

    Various Lexmark devices have CSRF that allows an attacker to modify the configuration of the device.

  • CVE-2022-29850HigAug 26, 2022
    risk 0.53cvss 8.1epss 0.01

    Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to maintain persistence across reboots.

  • CVE-2019-16758HigNov 21, 2019
    risk 0.53cvss 7.5epss 0.17

    In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal technique using /../../../ or ..%2F..%2F..%2F to obtain local files on the host operating system.

  • CVE-2023-22960HigJan 23, 2023
    risk 0.51cvss 7.5epss 0.28

    Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.

  • CVE-2021-35469HigJul 14, 2021
    risk 0.51cvss 7.8epss 0.00

    The Lexmark Printer Software G2, G3 and G4 Installation Packages have a local escalation of privilege vulnerability due to a registry entry that has an unquoted service path.

  • CVE-2016-5646HigJan 6, 2017
    risk 0.51cvss 7.8epss 0.02

    An exploitable heap overflow vulnerability exists in the Compound Binary File Format (CBFF) parser functionality of Lexmark Perceptive Document Filters library. A specially crafted CBFF file can cause a code execution. An attacker can send a malformed file to trigger this…

  • CVE-2023-40239HigSep 1, 2023
    risk 0.49cvss 7.5epss 0.00

    Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or…

  • CVE-2022-24935HigApr 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Lexmark products through 2022-02-10 have Incorrect Access Control.

  • CVE-2018-18894HigMar 10, 2020
    risk 0.49cvss 7.5epss 0.02

    Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server.

Page 1 of 2