Vulnerabilities > Cisco > Call Manager > 4.0.2a.sr2b

DATE CVE VULNERABILITY TITLE RISK
2006-01-22 CVE-2006-0368 Remote Denial Of Service vulnerability in Cisco CallManager
Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allow remote attackers to (1) cause a denial of service (CPU and memory consumption) via a large number of open TCP connections to port 2000 and (2) cause a denial of service (fill the Windows Service Manager communication queue) via a large number of TCP connections to port 2001, 2002, or 7727.
network
low complexity
cisco
7.8
2006-01-22 CVE-2006-0367 Remote Privilege Escalation vulnerability in Cisco CallManager CCMAdmin
Unspecified vulnerability in Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allows remote authenticated users with read-only administrative privileges to obtain full administrative privileges via a "crafted URL on the CCMAdmin web page."
network
low complexity
cisco
6.5