VendorsKyoceramitascanner_file_utilityall versions
Vulnerabilities

Kyoceramita Scanner File Utility

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2008-7109
The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to bypass authorization and upload arbitrary files to the client system via a modified program that does not prompt the user for a password.
Published 2009-08-28 · Modified
10.0EPSS 0.041
CVE-2008-7111
The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 does not restrict the filenames or extensions of uploaded files, which makes it easier for remote attackers to execute arbitrary code or overwrite files by leveraging CVE-2008-7110 and CVE-2008-7109.
Published 2009-08-28 · Modified
9.3EPSS 0.034
CVE-2008-7110
Directory traversal vulnerability in the Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to upload files to arbitrary locations via a .. (dot dot) in a request.
Published 2009-08-28 · Modified
7.81 PoCEPSS 0.029
CVE-2008-7113
The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 uses a small space of predictable user identification numbers for access control, which allows remote attackers to upload documents via a brute force attack.
Published 2009-08-28 · Modified
6.4EPSS 0.012
CVE-2008-7112
The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to cause a denial of service (hang or crash) via invalid field length values in a malformed (1) document or (2) request.
Published 2009-08-28 · Modified
5.0EPSS 0.014