Vulnerabilities > Avaya > IP Office > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-06-25 CVE-2024-4197 Unrestricted Upload of File with Dangerous Type vulnerability in Avaya IP Office
An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component.
network
low complexity
avaya CWE-434
critical
9.8
2024-06-25 CVE-2024-4196 Unspecified vulnerability in Avaya IP Office
An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially crafted web request to the Web Control component.
network
low complexity
avaya
critical
9.8
2017-11-10 CVE-2017-11309 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Avaya IP Office
Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response.
network
low complexity
avaya CWE-119
critical
9.6