Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 1.3% | — | Xerox Workcentre | 11/12/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 have unknown impact and attack vectors, related to (1) an Immediate Image Overwrite (IIO) error message at the Local User Interface (LUI) if overwrite fails, (2) an… | |
| Modificada | Alta (10) | 1.4% | — | Xerox Workcentre | 11/12/2006 | 16/6/2026 | The httpd.conf file in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 configures port 443 to be always active, which has unknown impact and remote attack vectors. | |
| Modificada | Media (5.8) | 0.27% | — | Xerox Workcentre | 11/12/2006 | 16/6/2026 | Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 do not check the Fully Qualified Domain Name (FQDN) during a "Validate Repository SSL Certificate" scan, which has unknown impact and attack vectors, possibly related to spoofed certificates. | |
| Modificada | Alta (7.5) | 1.4% | — | Xerox Workcentre | 10/12/2006 | 16/6/2026 | The SNMP implementation in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 does not generate authentication failure traps, which allows remote attackers to more easily gain system access and obtain sensitive information via a brute force attack. | |
| Modificada | Alta (7.5) | 1.3% | — | Xerox Workcentre 232Xerox Workcentre 238Xerox Workcentre 245Xerox Workcentre 255+2 | 10/12/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allow remote attackers to have an unspecified impact via unspecified vectors relating to "HTTP Security issues." | |
| Modificada | Media (5) | 1.3% | — | Xerox Workcentre | 10/12/2006 | 16/6/2026 | Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 does not record accurate timestamps, which makes it easier for remote attackers to avoid detection when an audit tries to rely on these timestamps. | |
| Modificada | Media (5) | 1.3% | — | Xerox Workcentre | 10/12/2006 | 16/6/2026 | Unspecified vulnerability in the Scan-to-mailbox feature in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allows remote attackers to download certain files via unspecified vectors. | |
| Modificada | Media (5) | 1.1% | — | Xerox Workcentre | 10/12/2006 | 16/6/2026 | Unspecified vulnerability in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allows attackers to modify signatures of e-mail messages via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.4% | — | Xerox Workcentre 232Xerox Workcentre 238Xerox Workcentre 245Xerox Workcentre 255+2 | 10/12/2006 | 16/6/2026 | Unspecified vulnerability in the Web User Interface in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows remote attackers to bypass authentication controls via unknown vectors. | |
| Modificada | Alta (7.8) | 1.4% | — | Xerox Workcentre 232Xerox Workcentre 238Xerox Workcentre 245Xerox Workcentre 255+2 | 10/12/2006 | 16/6/2026 | Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows remote attackers to download the audit log and obtain potentially sensitive information via unspecified vectors. | |
| Modificada | Media (4.6) | 0.31% | — | Xerox Workcentre 232Xerox Workcentre 238Xerox Workcentre 245Xerox Workcentre 255+2 | 10/12/2006 | 16/6/2026 | Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows local users to bypass security controls and boot Alchemy via certain alternate boot media, as demonstrated by a USB thumb drive. | |
| Modificada | Media (6.8) | 1.1% | — | Xerox Workcentre 232Xerox Workcentre 238Xerox Workcentre 245Xerox Workcentre 255+2 | 10/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Network controller in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows remote attackers to inject arbitrary web script or HTML via HTTP TRACE messages. | |
| Modificada | Alta (7.8) | 1.0% | — | Xerox Workcentre | 10/12/2006 | 16/6/2026 | ops3-dmn in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows attackers to cause a denial of service (application crash and core dump) via a certain PS file. | |
| Modificada | Alta (7.5) | 1.5% | — | Xerox Workcentre | 10/12/2006 | 16/6/2026 | Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allow remote attackers to gain access via unspecified vectors related to "browser permissions." | |
| Modificada | Media (5) | 1.1% | — | Xerox Workcentre | 10/12/2006 | 16/6/2026 | Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allows attackers to modify certain configuration settings via unspecified vectors involving the "TFTP/BOOTP auto configuration option." | |
| Modificada | Media (4.9) | 0.32% | — | Xerox Workcentre 232Xerox Workcentre 238Xerox Workcentre 245Xerox Workcentre 255+2 | 10/12/2006 | 16/6/2026 | Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 leaves sensitive user data in http.log after an Immediate Image Overwrite (IIO), which allows local users to obtain the data by reading the http.log file. | |
| Modificada | Alta (7.5) | 2.9% | — | Xerox Workcentre | 10/12/2006 | 16/6/2026 | The Web User Interface in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 allows remote attackers to execute arbitrary commands via unspecified vectors involving "command injection" in (1) the TCP/IP hostname, (2) Scan-to-mailbox folder names, and (3)… | |
| Modificada | Alta (7.8) | 1.6% | — | Xerox Workcentre 232Xerox Workcentre 238Xerox Workcentre 245Xerox Workcentre 255+2 | 10/12/2006 | 16/6/2026 | Web services in Xerox WorkCentre and WorkCentre Pro before 12.060.17.000, 13.x before 13.060.17.000, and 14.x before 14.060.17.000 do not require HTTPS, which allows remote attackers to obtain sensitive information by sniffing the unencrypted HTTP traffic. | |
| Modificada | Alta (7.5) | 3.4% | — | Xerox Workcentre 232Xerox Workcentre 238Xerox Workcentre 245Xerox Workcentre 255+2 | 13/10/2006 | 16/6/2026 | The ESS/ Network Controller and MicroServer Web Server components of Xerox WorkCentre and WorkCentre Pro 232, 238, 245, 255, 265 and 275 allow remote attackers to bypass authentication and execute arbitrary code via "WebUI command injection on TCP/IP hostname." | |
| Modificada | Alta (7.5) | 2.2% | — | Dell 3000cnDell 3010cnDell 3100cnDell 3110cn+15 | 25/8/2006 | 16/6/2026 | Fuji Xerox Printing Systems (FXPS) print engine, as used in products including (1) Dell 3000cn through 5110cn and (2) Fuji Xerox DocuPrint firmware before 20060628 and Network Option Card firmware before 5.13, allows remote attackers to use the FTP printing interface as a proxy ("FTP bounce") by using arbitrary PORT… | |
| Modificada | Media (6.4) | 1.9% | — | Dell 3000cnDell 3010cnDell 3100cnDell 3110cn+15 | 25/8/2006 | 16/6/2026 | The embedded HTTP server in Fuji Xerox Printing Systems (FXPS) print engine, as used in products including (1) Dell 3000cn through 5110cn and (2) Fuji Xerox DocuPrint firmware before 20060628 and Network Option Card firmware before 5.13, does not properly perform authentication for HTTP requests, which allows remote… | |
| Modificada | Media (6.4) | 1.7% | — | Xerox Copycentre C65 FirmwareXerox Copycentre C75 FirmwareXerox Copycentre C90 FirmwareXerox Workcentre PRO 65 Firmware+2 | 10/3/2006 | 16/6/2026 | Unspecified vulnerability in the ESS/ Network Controller in Xerox CopyCentre and Xerox WorkCentre Pro, running software 1.001.02.073 or earlier, or 1.001.02.074 before 1.001.02.715, causes the Immediate Image Overwrite feature to fail after a power loss, which could leave data exposed to attack. | |
| Modificada | Media (5) | 3.2% | — | Xerox Copycentre C65 FirmwareXerox Copycentre C75 FirmwareXerox Copycentre C90 FirmwareXerox Workcentre PRO 65 Firmware+2 | 10/3/2006 | 16/6/2026 | Unspecified vulnerability in the web server code in Xerox CopyCentre and Xerox WorkCentre Pro, running software 1.001.02.073 or earlier, or 1.001.02.074 before 1.001.02.715, allows remote attackers to cause a denial of service (memory corruption) via unknown vectors. | |
| Modificada | Media (5) | 2.7% | — | Xerox Copycentre C65Xerox Copycentre C75Xerox Copycentre C90Xerox Workcentre 65+2 | 10/3/2006 | 16/6/2026 | Buffer overflow in the PostScript file interpreter code for Xerox CopyCentre and Xerox WorkCentre Pro, running software 1.001.02.073 or earlier, or 1.001.02.074 before 1.001.02.715, allows attackers to cause a denial of service via unknown vectors. | |
| Modificada | Media (5) | 3.9% | — | Xerox Copycentre C65 FirmwareXerox Copycentre C75 FirmwareXerox Copycentre C90 FirmwareXerox Workcentre PRO 65 Firmware+2 | 10/3/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in Xerox CopyCentre and Xerox WorkCentre Pro, running software 1.001.02.073 or earlier, or 1.001.02.074 before 1.001.02.715, allow remote attackers to cause an unspecified denial of service via a crafted PostScript file that will (1) "navigate through the directory" or (2) a "file… |