Vulnerabilities > Cisco > IP Phone 8845

DATE CVE VULNERABILITY TITLE RISK
2020-01-26 CVE-2019-16008 Cross-site Scripting vulnerability in Cisco products
A vulnerability in the web-based GUI of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of an affected system.
network
cisco CWE-79
3.5
2019-05-03 CVE-2019-1635 Improper Handling of Exceptional Conditions vulnerability in Cisco products
A vulnerability in the call-handling functionality of Session Initiation Protocol (SIP) Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthenticated, remote attacker to cause an affected phone to reload unexpectedly, resulting in a temporary denial of service (DoS) condition.
network
low complexity
cisco CWE-755
7.8
2019-02-21 CVE-2019-1684 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco products
A vulnerability in the Cisco Discovery Protocol or Link Layer Discovery Protocol (LLDP) implementation for the Cisco IP Phone 7800 and 8800 Series could allow an unauthenticated, adjacent attacker to cause an affected phone to reload unexpectedly, resulting in a temporary denial of service (DoS) condition.
low complexity
cisco CWE-119
6.1
2019-01-10 CVE-2018-0461 Code Injection vulnerability in Cisco IP Phone 8800 Series Firmware 12.5(1)
A vulnerability in the Cisco IP Phone 8800 Series Software could allow an unauthenticated, remote attacker to conduct an arbitrary script injection attack on an affected device.
network
cisco CWE-94
6.8
2018-07-16 CVE-2018-0341 OS Command Injection vulnerability in Cisco IP Phone Multiplatform Firmware 11.1(2)
A vulnerability in the web-based UI of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware before 11.2(1) could allow an authenticated, remote attacker to perform a command injection and execute commands with the privileges of the web server.
network
low complexity
cisco CWE-78
critical
9.0
2018-06-07 CVE-2018-0332 Unspecified vulnerability in Cisco IP Phone Firmware and Unified IP Phone Firmware
A vulnerability in the Session Initiation Protocol (SIP) ingress packet processing of Cisco Unified IP Phone software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
network
low complexity
cisco
5.0
2018-06-07 CVE-2018-0316 Improper Handling of Exceptional Conditions vulnerability in Cisco IP Phone Firmware 11.1(2)
A vulnerability in the Session Initiation Protocol (SIP) call-handling functionality of Cisco IP Phone 6800, 7800, and 8800 Series Phones with Multiplatform Firmware could allow an unauthenticated, remote attacker to cause an affected phone to reload unexpectedly, resulting in a temporary denial of service (DoS) condition.
network
low complexity
cisco CWE-755
7.8