Vulnerabilities > Cisco > Unified Communications Manager > 4.2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2013-12-21 | CVE-2013-6978 | Information Exposure vulnerability in Cisco Unified Communications Manager The disaster recovery system (DRS) component in Cisco Unified Communications Manager (UCM) 9.1(1) and earlier allows remote authenticated users to obtain sensitive device information by reading "extraneous information" in HTML source code, aka Bug ID CSCuj39249. | 4.0 |
2013-11-18 | CVE-2013-6689 | Improper Input Validation vulnerability in Cisco Unified Communications Manager Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier allows local users to bypass file permissions, and read, modify, or create arbitrary files, via an "overload" of the command-line utility, aka Bug ID CSCui58229. | 6.9 |
2013-11-18 | CVE-2013-6688 | Path Traversal vulnerability in Cisco Unified Communications Manager Directory traversal vulnerability in the license-upload interface in the Enterprise License Manager (ELM) component in Cisco Unified Communications Manager 9.1(1) and earlier allows remote authenticated users to create arbitrary files via a crafted path, aka Bug ID CSCui58222. | 6.3 |
2013-08-22 | CVE-2013-3453 | Resource Management Errors vulnerability in Cisco Unified Communications Manager and Unified Presence Memory leak in Cisco Unified Communications Manager IM and Presence Service before 8.6(5)SU1 and 9.x before 9.1(2), and Cisco Unified Presence, allows remote attackers to cause a denial of service (memory and CPU consumption) by making many TCP connections to port (1) 5060 or (2) 5061, aka Bug ID CSCud84959. | 7.8 |
2011-08-29 | CVE-2011-2560 | Resource Management Errors vulnerability in Cisco Unified Communications Manager The Packet Capture Service in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x does not properly handle idle TCP connections, which allows remote attackers to cause a denial of service (memory consumption and restart) by making many connections, aka Bug ID CSCtf97162. | 7.8 |
2010-08-26 | CVE-2010-2838 | Unspecified vulnerability in Cisco Unified Communications Manager The SendCombinedStatusInfo implementation in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.0SU before 7.0(2a)SU3, 7.1 before 7.1(5), and 8.0 before 8.0(3) allows remote attackers to cause a denial of service (process failure) via a malformed SIP REGISTER message, aka Bug ID CSCtf66305. | 7.8 |
2010-08-26 | CVE-2010-2837 | Unspecified vulnerability in Cisco Unified Communications Manager The SIPStationInit implementation in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.1SU before 6.1(5)SU1, 7.0SU before 7.0(2a)SU3, 7.1SU before 7.1(3b)SU2, 7.1 before 7.1(5), and 8.0 before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP message, aka Bug ID CSCtd17310. | 7.8 |
2010-03-05 | CVE-2010-0592 | Denial of Service vulnerability in Cisco Unified Communications Manager CTI Manager Service The CTI Manager service in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x before 4.3(2)sr1a, 6.x before 6.1(3), 7.0x before 7.0(2), 7.1x before 7.1(2), and 8.x before 8.0(1) allows remote attackers to cause a denial of service (service failure) via a malformed message, aka Bug ID CSCsu31800. | 7.8 |
2010-03-05 | CVE-2010-0587 | Denial of Service vulnerability in Cisco Unified Communications Manager SCCP (CVE-2010-0587) Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x before 4.3(2)SR2, 6.x before 6.1(5), 7.x before 7.1(3a)su1, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SCCP StationCapabilitiesRes message with an invalid MaxCap field, aka Bug ID CSCtc38985. | 7.8 |
2009-08-27 | CVE-2009-2050 | Unspecified vulnerability in Cisco Unified Communications Manager Cisco Unified Communications Manager (aka CUCM, formerly CallManager) before 6.1(1) allows remote attackers to cause a denial of service (voice-services outage) via a malformed header in a SIP message, aka Bug ID CSCsi46466. | 7.8 |