Lexmark International Inc.

First CVE: Feb 28, 2024Active for: 2 years
21
CVEs Published
More CVEs Published than 41% of tracked CNAs
7.0
Avg CVEs / Year
More Avg CVEs / Year than 42% of tracked CNAs
8.0
Avg CVSS Score
Higher Avg CVSS Score than 86% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Lexmark International Inc. as a CNA, 9.5% affect products that Lexmark International Inc. develops as a vendor.

90.5%
Self-reported: 2Third-party: 19

Of all the CVEs published that affect products developed by Lexmark International Inc., 2.9% are self-published by Lexmark International Inc. as a CNA.

97.1%
Self-published: 2Published by other CNAs: 66

Trends Over Time

The number and severity of CVEs published by Lexmark International Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 28, 2024
2 years ago
Most Recent CVE
Feb 3, 2026
171 days ago

Top CVEs

All CVEs published by Lexmark International Inc. as a CNA, regardless of affected vendor or product.

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An untrusted search path vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an attacker to exe
Feb 3, 20269.330NONO
A relative path traversal vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an attacker to ex
Feb 3, 20268.828NONO
The vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user and/or modify the contents of any data on the filesystem.
Feb 13, 20259.128NONO
A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the Lexmark Print Management Client.
Feb 11, 20259.328NONO
A heap corruption vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary cod
Feb 28, 20249.028NONO
Improper Restriction of XML External Entity Reference in various Lexmark printer drivers for Windows allows attacker to disclose sensitive information to an arbitrary URL.
Aug 19, 20258.226NONO
A buffer overflow vulnerability has been identified in the Internet Printing Protocol (IPP) in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute
Jan 18, 20258.826NONO
The SE menu contains information used by Lexmark to diagnose device errors. A vulnerability in one of the SE menu routines can be leveraged by an attacker to execute arbitrary code
Feb 28, 20249.125NONO
A buffer overflow vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary cod
Feb 28, 20249.025NONO
A missing authorization vulnerability in Lexmark Cloud Services badge management allows attacker to reassign badges within their organization
Aug 19, 20258.524NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA21 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local2 (9.5%)
Network17 (81.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (9.5%)
Attack Complexity
Low17 (81.0%)
High4 (19.0%)
Unknown0 (0.0%)
User Interaction
None20 (95.2%)
Unknown0 (0.0%)
Required1 (4.8%)
Privileges Required
Low2 (9.5%)
High3 (14.3%)
None16 (76.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Lexmark International Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Lexmark International Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs