Vulnerabilities > Alcatel Lucent > Omnipcx > 7.1

DATE CVE VULNERABILITY TITLE RISK
2011-03-08 CVE-2011-0344 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Alcatel-Lucent Omnipcx
Multiple stack-based buffer overflows in unspecified CGI programs in the Unified Maintenance Tool web interface in the embedded web server in the Communication Server (CS) in Alcatel-Lucent OmniPCX Enterprise before R9.0 H1.301.50 allow remote attackers to execute arbitrary code via crafted HTTP headers.
low complexity
alcatel-lucent CWE-119
5.8
2007-09-18 CVE-2007-3010 Improper Input Validation vulnerability in Alcatel-Lucent Omnipcx 7.1
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.
network
low complexity
alcatel-lucent CWE-20
critical
10.0