Vulnerabilities > Cisco > IP Phone 8800 Series Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2019-01-10 CVE-2018-0461 Code Injection vulnerability in Cisco IP Phone 8800 Series Firmware 12.5(1)
A vulnerability in the Cisco IP Phone 8800 Series Software could allow an unauthenticated, remote attacker to conduct an arbitrary script injection attack on an affected device.
network
low complexity
cisco CWE-94
8.8
2016-08-22 CVE-2016-1479 Improper Input Validation vulnerability in Cisco IP Phone 8800 Series Firmware 11.0(1)
Cisco IP Phone 8800 devices with software 11.0(1) allow remote attackers to cause a denial of service (memory corruption) via a crafted HTTP request, aka Bug ID CSCuz03038.
network
low complexity
cisco CWE-20
7.5
2016-06-23 CVE-2016-1435 Permissions, Privileges, and Access Controls vulnerability in Cisco IP Phone 8800 Series Firmware 11.0(1)
Cisco 8800 phones with software 11.0(1) do not properly enforce mounted-filesystem permissions, which allows local users to write to arbitrary files by leveraging shell access, aka Bug ID CSCuz03014.
local
high complexity
cisco CWE-264
7.0
2016-06-10 CVE-2016-1421 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco IP Phone 8800 Series Firmware 11.0(1)
A vulnerability in the web application for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or cause a reload of an affected IP phone, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-119
7.5
2016-06-04 CVE-2016-1403 Improper Input Validation vulnerability in Cisco IP Phone 8800 Series Firmware
CISCO IP 8800 phones with software 11.0.1 and earlier allow local users to gain privileges for OS command execution via crafted CLI commands, aka Bug ID CSCuz03005.
local
low complexity
cisco CWE-20
7.8
2016-04-21 CVE-2015-6360 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco products
The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted fields in SRTP packets, aka Bug ID CSCux00686.
network
low complexity
cisco CWE-119
7.5