Lexmark
857 known vulnerabilities
Top Products
Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixe
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4).
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 1 of 4).
Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.
Certain Lexmark devices through 2023-02-19 have an Integer Overflow.
Certain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.
Certain Lexmark devices through 2023-02-19 access a Resource By Using an Incompatible Type.
In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.
Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.
Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to
Lexmark products through 2022-02-10 have Incorrect Access Control.
PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal
The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” fea
Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.
Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to
Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.
The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below,
The Lexmark Printer Software G2, G3 and G4 Installation Packages have a local escalation of privilege vulnerability due
A cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x befo
A cross-site scripting (XSS) vulnerability in Lexmark Pro910 series inkjet and other discontinued products.
Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the
Lexmark Markvision Enterprise before 2.3.0 misuses the Apache Commons Collections Library, leading to remote code execut
Lexmark X, W, T, E, and C devices before 2012-02-09 allow attackers to obtain sensitive information by reading passwords
Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a
Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading file
Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected p
Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affecte
Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web
Directory traversal vulnerability in the ReportDownloadServlet servlet in Lexmark MarkVision Enterprise before 2.1 allow
Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allo
In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal tech
Various Lexmark products have a Buffer Overflow (issue 3 of 3).
Various Lexmark products have a Buffer Overflow (issue 2 of 3).
Various Lexmark printers contain a denial of service vulnerability in the SNMP service that can be exploited to crash th
Various Lexmark products have an Integer Overflow.
The legacy finger service (TCP port 79) is enabled by default on various older Lexmark devices.
Various Lexmark products have CSRF.
Various Lexmark products have Incorrect Access Control (issue 2 of 2).
Various Lexmark products have Incorrect Access Control (issue 1 of 2).
Various Lexmark products have Incorrect Access Control.
Various Lexmark devices have a Buffer Overflow (issue 1 of 2).
Various Lexmark devices have a Buffer Overflow (issue 2 of 2).
On certain Lexmark devices that communicate with an LDAP or SMTP server, a malicious administrator can discover LDAP or
Certain Lexmark CX, MX, X, XC, XM, XS, and 6500e devices before 2019-02-11 allow remote attackers to erase stored shortc
Lexmark Scan To Network (SNF) 3.2.9 and earlier stores network configuration credentials in plaintext and transmits them
An exploitable code execution vulnerability exists in the image rendering functionality of Lexmark Perceptive Document F
An exploitable use-after-free exists in the PDF parsing functionality of Lexmark Perspective Document Filters 11.3.0.240
An exploitable arbitrary read exists in the XLS parsing of the Lexmark Perspective Document Filters conversion functiona
Frequently Asked Questions
How many CVEs affect Lexmark?
Lexmark has 857 CVE records in our database, including 366 critical and 223 high severity vulnerabilities.
What are the most severe Lexmark vulnerabilities?
Lexmark has 366 critical severity (CVSS 9.0+) and 223 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Lexmark vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Lexmark products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Lexmark Vulnerabilities
CyberStrike scans your infrastructure for Lexmark vulnerabilities and provides real-time remediation guidance.
Get Started