Vulnerabilities > Cisco > Unified Communications Manager > 5.1.1c

DATE CVE VULNERABILITY TITLE RISK
2009-08-27 CVE-2009-2051 Unspecified vulnerability in Cisco IOS and Unified Communications Manager
Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), and 7.x before 7.1(2) allow remote attackers to cause a denial of service (device reload or voice-services outage) via a malformed SIP INVITE message that triggers an improper call to the sipSafeStrlen function, aka Bug IDs CSCsz40392 and CSCsz43987.
network
low complexity
cisco
7.8
2009-08-27 CVE-2009-2050 Unspecified vulnerability in Cisco Unified Communications Manager
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) before 6.1(1) allows remote attackers to cause a denial of service (voice-services outage) via a malformed header in a SIP message, aka Bug ID CSCsi46466.
network
low complexity
cisco
7.8
2008-06-26 CVE-2008-2062 Permissions, Privileges, and Access Controls vulnerability in Cisco Unified Communications Manager
The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) before 4.2(3)SR4, and 4.3 before 4.3(2)SR1, allows remote attackers to bypass authentication, and obtain cluster configuration information and statistics, via a direct TCP connection to the service port, aka Bug ID CSCsq35151.
network
low complexity
cisco CWE-264
5.0
2008-06-26 CVE-2008-2061 Improper Input Validation vulnerability in Cisco Unified Communications Manager
The Computer Telephony Integration (CTI) Manager service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3c) and 6.x before 6.1(2) allows remote attackers to cause a denial of service (TSP crash) via malformed network traffic to TCP port 2748.
network
low complexity
cisco CWE-20
7.8
2008-05-16 CVE-2008-1748 Improper Input Validation vulnerability in Cisco Unified Communications Manager
Cisco Unified Communications Manager 4.1 before 4.1(3)SR7, 4.2 before 4.2(3)SR4, 4.3 before 4.3(2), 5.x before 5.1(3), and 6.x before 6.1(1) does not properly validate SIP URLs, which allows remote attackers to cause a denial of service (service interruption) via a SIP INVITE message, aka Bug ID CSCsl22355.
network
low complexity
cisco CWE-20
7.8
2008-05-16 CVE-2008-1747 Improper Input Validation vulnerability in Cisco Unified Communications Manager
Unspecified vulnerability in Cisco Unified Communications Manager 4.1 before 4.1(3)SR6, 4.2 before 4.2(3)SR3, 4.3 before 4.3(2), 5.x before 5.1(3), and 6.x before 6.1(1) allows remote attackers to cause a denial of service (CCM service restart) via an unspecified SIP INVITE message, aka Bug ID CSCsk46944.
network
low complexity
cisco CWE-20
7.8
2008-05-16 CVE-2008-1743 Resource Management Errors vulnerability in Cisco Unified Communications Manager
Memory leak in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) and 6.x before 6.1(1) allows remote attackers to cause a denial of service (memory consumption and service interruption) via a series of malformed TCP packets, aka Bug ID CSCsi98433.
network
low complexity
cisco CWE-399
7.8
2007-10-18 CVE-2007-5538 Buffer Errors vulnerability in Cisco products
Buffer overflow in the Centralized TFTP File Locator Service in Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(3), and Unified CallManager 5.0, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors involving the processing of filenames, aka CSCsh47712.
network
low complexity
cisco CWE-119
critical
10.0
2007-10-18 CVE-2007-5537 Resource Management Errors vulnerability in Cisco products
Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(2), and Unified CallManager 5.0, allow remote attackers to cause a denial of service (kernel panic) via a flood of SIP INVITE messages to UDP port 5060, which triggers resource exhaustion, aka CSCsi75822.
network
low complexity
cisco CWE-399
7.8