VYPR

Vendor CVEs

Lexmark

All CVEs

88 total · sorted by risk
  • CVE-2011-3269HigMar 9, 2020
    risk 0.49cvss 7.5epss 0.01

    Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a hidden email address in a Scan To Email shortcut.

  • CVE-2014-8742HigJan 27, 2020
    risk 0.49cvss 7.5epss 0.04

    Directory traversal vulnerability in the ReportDownloadServlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to read arbitrary files via unspecified vectors.

  • CVE-2019-9931HigAug 28, 2019
    risk 0.49cvss 7.5epss 0.01

    Various Lexmark printers contain a denial of service vulnerability in the SNMP service that can be exploited to crash the device.

  • CVE-2017-2822HigSep 5, 2017
    risk 0.49cvss 7.5epss 0.02

    An exploitable code execution vulnerability exists in the image rendering functionality of Lexmark Perceptive Document Filters 11.3.0.2400. A specifically crafted PDF can cause a function call on a corrupted DCTStream to occur, resulting in user controlled data being written to…

  • CVE-2024-11345HigFeb 13, 2025
    risk 0.47cvss 7.3epss 0.00

    A heap-based memory vulnerability has been identified in the Postscript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.

  • CVE-2024-11344HigFeb 13, 2025
    risk 0.47cvss 7.3epss 0.00

    A type confusion vulnerability has been identified in the Postscript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.

  • CVE-2025-65081MedFeb 3, 2026
    risk 0.45cvss —epss 0.01

    An out-of-bounds read vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user.

  • CVE-2025-65080MedFeb 3, 2026
    risk 0.45cvss —epss 0.01

    A type confusion vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user.

  • CVE-2025-65079MedFeb 3, 2026
    risk 0.45cvss —epss 0.01

    A heap-based buffer overflow vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user.

  • CVE-2025-9269MedSep 9, 2025
    risk 0.45cvss —epss 0.00

    A Server-Side Request Forgery (SSRF) vulnerability has been identified in the embedded web server in various Lexmark devices. This vulnerability can be leveraged by an attacker to force the device to send an arbitrary HTTP request to a third-party server. Successful…

  • CVE-2019-10057MedAug 28, 2019
    risk 0.42cvss 6.5epss 0.00

    Various Lexmark products have CSRF.

  • CVE-2020-13481MedFeb 19, 2025
    risk 0.40cvss 6.1epss 0.00

    Certain Lexmark products through 2020-05-25 allow XSS which allows an attacker to obtain session credentials and other sensitive information.

  • CVE-2020-10094MedApr 28, 2020
    risk 0.35cvss 5.4epss 0.01

    A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x before LW74.VY4.P273; CX310 before LW74.GM2.P273; CX410 & XC2130 before LW74.GM4.P273; CX510 & XC2132 before LW74.GM7.P273; MS310, MS312, MS317 before…

  • CVE-2020-10093MedApr 28, 2020
    risk 0.35cvss 5.4epss 0.01

    A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products.

  • CVE-2011-4538MedMar 9, 2020
    risk 0.35cvss 5.3epss 0.01

    Lexmark X, W, T, E, and C devices before 2012-02-09 allow attackers to obtain sensitive information by reading passwords within exported settings.

  • CVE-2019-19773MedMar 6, 2020
    risk 0.35cvss 5.4epss 0.01

    Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.

  • CVE-2019-19772MedMar 6, 2020
    risk 0.35cvss 5.4epss 0.01

    Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.

  • CVE-2019-18791MedFeb 13, 2020
    risk 0.35cvss 5.4epss 0.01

    Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and other information via the users web browser.

  • CVE-2019-10059MedAug 28, 2019
    risk 0.35cvss 5.3epss 0.01

    The legacy finger service (TCP port 79) is enabled by default on various older Lexmark devices.

  • CVE-2019-9935MedAug 28, 2019
    risk 0.35cvss 5.3epss 0.01

    Various Lexmark products have Incorrect Access Control (issue 2 of 2).

  • CVE-2019-9934MedAug 28, 2019
    risk 0.35cvss 5.3epss 0.01

    Various Lexmark products have Incorrect Access Control (issue 1 of 2).

  • CVE-2019-6489MedFeb 11, 2019
    risk 0.35cvss 5.3epss 0.01

    Certain Lexmark CX, MX, X, XC, XM, XS, and 6500e devices before 2019-02-11 allow remote attackers to erase stored shortcuts.

  • CVE-2018-17944MedMar 12, 2019
    risk 0.32cvss 4.9epss 0.01

    On certain Lexmark devices that communicate with an LDAP or SMTP server, a malicious administrator can discover LDAP or SMTP credentials by changing that server's hostname to one that they control, and then capturing the credentials that are sent there. This occurs because…

  • CVE-2016-3145MedApr 22, 2016
    risk 0.30cvss 4.6epss 0.00

    Lexmark printers with firmware ATL before ATL.021.063, CB before CB.021.063, PP before PP.021.063, and YK before YK.021.063 mishandle Erase Printer Memory and Erase Hard Disk actions, which allows physically proximate attackers to obtain sensitive information via direct read…

  • CVE-2023-50738MedJan 17, 2025
    risk 0.28cvss 4.3epss 0.00

    A new feature to prevent Firmware downgrades was recently added to some Lexmark products. A method to override this downgrade protection has been identified.

  • CVE-2017-2806MedApr 20, 2017
    risk 0.28cvss 4.3epss 0.01

    An exploitable arbitrary read exists in the XLS parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted XLS document can lead to a arbitrary read resulting in memory disclosure. The vulnerability was confirmed on versions 11.3.0.2228 and…

  • CVE-2010-0619Mar 24, 2010
    risk 0.03cvss —epss 0.05

    Stack-based buffer overflow in the base, IPDS DLE, Forms DLE, Barcode DLE, Prescribe DLE, and Printcryption DLE components on certain Lexmark laser printers and multi-function printers allows remote attackers to execute arbitrary code or cause a denial of service (device hang)…

  • CVE-2004-0740Jul 27, 2004
    risk 0.03cvss —epss 0.03

    The HTTP server in Lexmark T522 and possibly other models allows remote attackers to cause a denial of service (server crash, reload, or hang) via an HTTP header with a long Host field, possibly triggering a buffer overflow.

  • CVE-2014-9375Feb 16, 2015
    risk 0.00cvss —epss 0.03

    Directory traversal vulnerability in the LibraryFileUploadServlet servlet in Lexmark Markvision Enterprise allows remote authenticated users to write to and execute arbitrary files via a .. (dot dot) in a file path in a ZIP archive.

  • CVE-2013-6033Feb 4, 2014
    risk 0.00cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities on Lexmark W840 through LS.HA.P252, T64x before LS.ST.P344, C935dn through LC.JO.P091, C920 through LS.TA.P152, C53x through LS.SW.P069, C52x through LS.FA.P150, E450 through LM.SZ.P124, E350 through LE.PH.P129, and E250…

  • CVE-2013-6032Feb 4, 2014
    risk 0.00cvss —epss 0.03

    cgi-bin/postpf/cgi-bin/dynamic/config/config.html on Lexmark X94x before LC.BR.P142, X85x through LC4.BE.P487, X644 and X646 before LC2.MC.P374, X642 through LC2.MB.P318, W840 through LS.HA.P252, T64x before LS.ST.P344, X64xef through LC2.TI.P325, C935dn through LC.JO.P091, C920…

  • CVE-2013-3055Apr 25, 2013
    risk 0.00cvss —epss 0.04

    Lexmark Markvision Enterprise before 1.8 provides a diagnostic interface on TCP port 9789, which allows remote attackers to execute arbitrary code, change the configuration, or obtain sensitive fleet-management information via unspecified vectors.

  • CVE-2010-0101May 4, 2010
    risk 0.00cvss —epss 0.01

    The embedded HTTP server in multiple Lexmark laser and inkjet printers and MarkNet devices, including X94x, W840, T656, N4000, E462, C935dn, 25xxN, and other models, allows remote attackers to cause a denial of service (operating system halt) via a malformed HTTP Authorization…

  • CVE-2010-0618Mar 24, 2010
    risk 0.00cvss —epss 0.01

    The flood-protection feature in the base, IPDS DLE, Forms DLE, Barcode DLE, Prescribe DLE, and Printcryption DLE components on certain Lexmark laser and inkjet printers and MarkNet devices allows remote attackers to cause a denial of service (TCP outage) by making many passive…

  • CVE-2006-0592Feb 8, 2006
    risk 0.00cvss —epss 0.04

    Unspecified vulnerability in the Lexmark Printer Sharing LexBce Server Service (LexPPS), possibly 8.29 and 9.41, allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based on a vague initial disclosure; details will be updated…

  • CVE-2006-0577Feb 8, 2006
    risk 0.00cvss —epss 0.00

    Lexmark X1185 printer allows local users to gain SYSTEM privileges by navigating to the "Appearance" dialog and selecting the "Additional styles (skins) are available on the Lexmark web site" option, which launches a web browser that is running with SYSTEM privileges.

  • CVE-2003-0036Feb 7, 2003
    risk 0.00cvss —epss 0.00

    ml85p, as included in the printer-drivers package for Mandrake Linux, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable filenames of the form "mlg85p%d".

  • CVE-2001-0044Feb 16, 2001
    risk 0.00cvss —epss 0.00

    Multiple buffer overflows in Lexmark MarkVision printer driver programs allows local users to gain privileges via long arguments to the cat_network, cat_paraller, and cat_serial commands.

Page 2 of 2