4 results (0.007 seconds)

CVSS: 7.8EPSS: 0%CPEs: 323EXPL: 0

25 Oct 2024 — Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword search input and improper processing of SOAP messages. Crafted HTTP requests may cause affected products crashed. • https://jvn.jp/en/vu/JVNVU95063136 • CWE-125: Out-of-bounds Read •

CVSS: 7.8EPSS: 0%CPEs: 434EXPL: 0

11 Jul 2023 — Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As for the affected products/models/versions, see the detailed information provided by each vendor. • https://jvn.jp/en/vu/JVNVU93767756/index.html • CWE-476: NULL Pointer Dereference •

CVSS: 8.8EPSS: 0%CPEs: 4EXPL: 1

19 Apr 2014 — Cross-site request forgery (CSRF) vulnerability in TopAccess (aka the web-based management utility) on TOSHIBA TEC e-Studio 232, 233, 282, and 283 devices allows remote attackers to hijack the authentication of administrators for requests that change passwords. Vulnerabilidad de CSRF en TopAccess (también conocido como la utilidad de gestión basada en web) en dispositivos TOSHIBA TEC e-Studio 232, 233, 282 y 283 permite a atacantes remotos secuestrar la autenticación de administradores para solicitudes que ... • https://www.exploit-db.com/exploits/29570 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 10.0EPSS: 15%CPEs: 64EXPL: 1

06 Apr 2012 — The TopAccess web-based management interface on TOSHIBA TEC e-Studio multi-function peripheral (MFP) devices with firmware 30x through 302, 35x through 354, and 4xx through 421 allows remote attackers to bypass authentication and obtain administrative privileges via unspecified vectors. La interfaz de gestión TopAccess basada en web en los dispositivos periféricos multifuncionales (MFP) TOSHIBA TEC e-Studio con firmware desde v30x hasta v302, desde v35x hasta v354, y v4xx hasta v421 permite a atacantes remo... • https://www.exploit-db.com/exploits/36238 • CWE-264: Permissions, Privileges, and Access Controls •