Vulnerabilities > Cisco > IP Communicator > 8.6

DATE CVE VULNERABILITY TITLE RISK
2012-08-06 CVE-2012-2490 Improper Input Validation vulnerability in Cisco IP Communicator 8.6
Cisco IP Communicator 8.6 allows man-in-the-middle attackers to modify the Certificate Trust List via unspecified vectors, aka Bug ID CSCtz01471.
network
low complexity
cisco CWE-20
5.0
2012-05-02 CVE-2012-0361 Permissions, Privileges, and Access Controls vulnerability in Cisco IP Communicator
The sccp-protocol component in Cisco IP Communicator (CIPC) 7.0 through 8.6 does not limit the rate of SCCP messages to Cisco Unified Communications Manager (CUCM), which allows remote attackers to cause a denial of service via vectors that trigger (1) on hook and (2) off hook messages, as demonstrated by a Plantronics headset, aka Bug ID CSCti40315.
network
low complexity
cisco CWE-264
5.0