Vulnerabilities > Avaya

DATE CVE VULNERABILITY TITLE RISK
2008-12-24 CVE-2008-5709 Improper Input Validation vulnerability in Avaya Communication Manager
Multiple unspecified vulnerabilities in the web management interface in Avaya Communication Manager (CM) 3.1 before 3.1.4 SP2, 4.0 before 4.0.3 SP1, and 5.0 before 5.0 SP3 allow remote authenticated users to execute arbitrary code via unknown attack vectors in the (1) Set Static Routes and (2) Backup History components.
network
low complexity
avaya CWE-20
critical
9.0
2008-08-25 CVE-2008-3778 Permissions, Privileges, and Access Controls vulnerability in Avaya Communication Manager and SIP Enablement Services
The remote management interface in SIP Enablement Services (SES) Server in Avaya SIP Enablement Services 5.0, and Communication Manager (CM) 5.0 on the S8300C with SES enabled, proceeds with Core router updates even when a login is invalid, which allows remote attackers to cause a denial of service (messaging outage) or gain privileges via an update request.
network
low complexity
avaya CWE-264
7.5
2008-08-25 CVE-2008-3777 Information Exposure vulnerability in Avaya Communication Manager and SIP Enablement Services
The SIP Enablement Services (SES) Server in Avaya SIP Enablement Services 5.0, and Communication Manager (CM) 5.0 on the S8300C with SES enabled, writes account names and passwords to the (1) alarm and (2) system logs during failed login attempts, which allows local users to obtain login credentials by reading these logs.
local
low complexity
avaya CWE-200
2.1
2008-07-09 CVE-2008-3081 Improper Input Validation vulnerability in Avaya Messaging Storage Server 3/3.1/4.0
Multiple unspecified "input validation" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Storage Server (MSS) 3.x and 4.0, and possibly Communication Manager 3.1.x, allow remote authenticated administrators to execute arbitrary commands as user vexvm via vectors related to (1) SFTP Remote Store configuration; (2) remote FTP storage settings; (3) name server lookup; (4) pinging another host; (5) TCP/IP Networking parameter configuration; (6) the external hosts configuration main page; (7) adding and changing external hosts; (8) Windows domain parameter configuration; (9) date, time, and NTP server configuration; (10) alarm settings; (11) the command line history form; (12) the maintenance form; and (13) the server events form.
network
low complexity
avaya CWE-20
6.5
2008-07-09 CVE-2008-2812 NULL Pointer Dereference vulnerability in multiple products
The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference of function pointers in (1) hamradio/6pack.c, (2) hamradio/mkiss.c, (3) irda/irtty-sir.c, (4) ppp_async.c, (5) ppp_synctty.c, (6) slip.c, (7) wan/x25_asy.c, and (8) wireless/strip.c in drivers/net/.
7.8
2007-11-05 CVE-2007-5830 Improper Input Validation vulnerability in Avaya Message Networking and Messaging Storage Server
Unspecified vulnerability in the administrative interface in Avaya Messaging Storage Server (MSS) 3.1 before SP1, and Message Networking (MN) 3.1, allows remote attackers to cause a denial of service via unspecified vectors related to "input validation."
network
low complexity
avaya CWE-20
7.8
2007-10-18 CVE-2007-5556 Improper Input Validation vulnerability in Avaya Voip Handset
Unspecified vulnerability in the Avaya VoIP Handset allows remote attackers to cause a denial of service (reboot) via crafted packets.
network
low complexity
avaya CWE-20
7.8
2007-09-19 CVE-2007-3286 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Avaya IP Soft Phone 5.2/6.0
Multiple buffer overflows in unspecified ActiveX controls in COM objects in Avaya IP Softphone R5.2 before SP3, and R6.0, allow remote attackers to execute arbitrary code via unspecified vectors.
network
avaya CWE-119
6.8
2007-04-30 CVE-2007-2374 Remote Code Execution vulnerability in Microsoft Windows
Unspecified vulnerability in Microsoft Windows 2000, XP, and Server 2003 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors.
network
microsoft avaya
critical
9.3
2007-03-30 CVE-2007-1765 Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7.
network
microsoft avaya
critical
9.3