Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
510039.1%CRITICAL

Related CVEs

10
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2024-48870Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scripting vulnerability. If crafted input is stored by an administrative user, malicious script may be executed on the web browsers of other victim users.MEDIUM4.824.2%Oct 25, 2024
CVE-2024-47801Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scripting vulnerability. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser.MEDIUM6.125.6%Oct 25, 2024
CVE-2024-47549Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of unintended data to HTTP response headers. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser.MEDIUM6.125.6%Oct 25, 2024
CVE-2024-47406Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulnerability.CRITICAL9.844.2%Oct 25, 2024
CVE-2024-47005Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users only, but insufficiently restricted. A non-administrative user may execute some configuration APIs.HIGH8.136.4%Oct 25, 2024
CVE-2024-45842Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability. Unintended internal files may be retrieved when processing crafted HTTP requests.MEDIUM5.341.4%Oct 25, 2024
CVE-2024-45829Sharp and Toshiba Tec MFPs provide the web page to download data, where query parameters in HTTP requests are improperly processed and resulting in an Out-of-bounds Read vulnerability. Crafted HTTP requests may cause affected products crashed.HIGH7.548.0%Oct 25, 2024
CVE-2024-43424Sharp and Toshiba Tec MFPs improperly process HTTP request headers, resulting in an Out-of-bounds Read vulnerability. Crafted HTTP requests may cause affected products crashed.HIGH7.549.6%Oct 25, 2024
CVE-2024-42420Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword search input and improper processing of SOAP messages. Crafted HTTP requests may cause affected products crashed.HIGH7.549.6%Oct 25, 2024
CVE-2023-29984Null pointer dereference vulnerability exists in multiple vendors MFPs and printers which implement Debut web server 1.2 or 1.3. Processing a specially crafted request may lead an affected product to a denial-of-service (DoS) condition. As for the affected products/models/versions, see the detailed information provided by each vendor.HIGH7.550.8%Jul 11, 2023