Vulnerabilities > Cisco > Session Initiation Protocol SIP Firmware

DATE CVE VULNERABILITY TITLE RISK
2008-02-15 CVE-2008-0531 Buffer Errors vulnerability in Cisco products
Heap-based buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SIP firmware might allow remote SIP servers to execute arbitrary code via a crafted challenge/response message.
network
cisco CWE-119
critical
9.3
2008-02-15 CVE-2008-0530 Buffer Errors vulnerability in Cisco products
Buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SCCP and SIP firmware might allow remote attackers to execute arbitrary code via a crafted DNS response.
network
low complexity
cisco CWE-119
critical
10.0
2008-02-15 CVE-2008-0529 Buffer Errors vulnerability in Cisco products
Buffer overflow in the telnet server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G running SCCP firmware might allow remote authenticated users to execute arbitrary code via a crafted command.
network
low complexity
cisco CWE-119
critical
10.0
2008-02-15 CVE-2008-0528 Buffer Errors vulnerability in Cisco products
Buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SIP firmware might allow remote attackers to execute arbitrary code via a SIP message with crafted MIME data.
network
low complexity
cisco CWE-119
critical
10.0
2008-02-15 CVE-2008-0527 Improper Input Validation vulnerability in Cisco products
The HTTP server in Cisco Unified IP Phone 7935 and 7936 running SCCP firmware allows remote attackers to cause a denial of service (reboot) via a crafted HTTP request.
network
low complexity
cisco CWE-20
7.8
2008-02-15 CVE-2008-0526 Improper Input Validation vulnerability in Cisco products
Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SCCP firmware allows remote attackers to cause a denial of service (reboot) via a long ICMP echo request (ping) packet.
network
low complexity
cisco CWE-20
7.8