CVE-2006-6430
- EPSS 0.44%
- Veröffentlicht 10.12.2006 11:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Web services in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 do not require HTTPS, which allows remote attackers to obtain sensitive information by sniffing the unencrypted HTTP tr...
CVE-2006-6434
- EPSS 0.46%
- Veröffentlicht 10.12.2006 11:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in the Web User Interface in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows remote attackers to bypass authentication controls via unknown vectors.
CVE-2006-6436
- EPSS 0.83%
- Veröffentlicht 10.12.2006 11:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in the Network controller in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows remote attackers to inject arbitrary web script or HTML vi...
CVE-2006-6438
- EPSS 0.06%
- Veröffentlicht 10.12.2006 11:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 leaves sensitive user data in http.log after an Immediate Image Overwrite (IIO), which allows local users to obtain the data by reading...
CVE-2006-6439
- EPSS 0.38%
- Veröffentlicht 10.12.2006 11:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows remote attackers to download the audit log and obtain potentially sensitive information via unspecified vectors.
CVE-2006-6440
- EPSS 0.61%
- Veröffentlicht 10.12.2006 11:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allow remote attackers to have an unspecified impact via unspecified vectors relating to "HTTP ...
CVE-2006-6441
- EPSS 0.06%
- Veröffentlicht 10.12.2006 11:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows local users to bypass security controls and boot Alchemy via certain alternate boot media, as demonstrated by a USB thumb drive.
CVE-2006-5290
- EPSS 1.58%
- Veröffentlicht 13.10.2006 20:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The ESS/ Network Controller and MicroServer Web Server components of Xerox WorkCentre and WorkCentre Pro 232, 238, 245, 255, 265 and 275 allow remote attackers to bypass authentication and execute arbitrary code via "WebUI command injection on TCP/IP...
CVE-2006-0825
- EPSS 1.08%
- Veröffentlicht 21.02.2006 23:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple unspecified vulnerabilities in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allow remote attackers to bypass authentication or gain "unauthor...
- EPSS 1.47%
- Veröffentlicht 21.02.2006 23:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Unspecified vulnerability in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allows remote attackers to cause a denial of service via a crafted Postscrip...