Vulnerabilities > Cisco > Unified Callmanager > 4.1.3.sr4

DATE CVE VULNERABILITY TITLE RISK
2008-05-16 CVE-2008-1744 Improper Input Validation vulnerability in Cisco products
The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager (CUCM) 4.1 before 4.1(3)SR7, 4.2 before 4.2(3)SR4, and 4.3 before 4.3(2) allows remote attackers to cause a denial of service (service crash) via malformed network traffic, aka Bug ID CSCsk46770.
network
low complexity
cisco CWE-20
7.8
2008-01-17 CVE-2008-0027 Buffer Errors vulnerability in Cisco products
Heap-based buffer overflow in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM) 4.2 before 4.2(3)SR3 and 4.3 before 4.3(1)SR1, and CallManager 4.0 and 4.1 before 4.1(3)SR5c, allows remote attackers to cause a denial of service or execute arbitrary code via a long request.
network
low complexity
cisco CWE-119
critical
10.0
2007-07-15 CVE-2006-5278 Heap Buffer Overflow vulnerability in Cisco products
Integer overflow in the Real-Time Information Server (RIS) Data Collector service (RisDC.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via crafted packets, resulting in a heap-based buffer overflow.
network
low complexity
cisco
critical
10.0
2007-07-15 CVE-2006-5277 Heap Buffer Overflow vulnerability in Cisco products
Off-by-one error in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via a crafted packet that triggers a heap-based buffer overflow.
network
cisco
critical
9.3