Vulnerabilities > Cisco > Unified Communications Manager > 5.1

DATE CVE VULNERABILITY TITLE RISK
2008-05-16 CVE-2008-1745 Improper Input Validation vulnerability in Cisco Unified Communications Manager
Cisco Unified Communications Manager (CUCM) 5.x before 5.1(2) and 6.x before 6.1(1) allows remote attackers to cause a denial of service (service interruption) via a SIP JOIN message with a malformed header, aka Bug ID CSCsi48115.
network
low complexity
cisco CWE-20
7.8
2008-05-16 CVE-2008-1743 Resource Management Errors vulnerability in Cisco Unified Communications Manager
Memory leak in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) and 6.x before 6.1(1) allows remote attackers to cause a denial of service (memory consumption and service interruption) via a series of malformed TCP packets, aka Bug ID CSCsi98433.
network
low complexity
cisco CWE-399
7.8
2008-05-16 CVE-2008-1742 Resource Management Errors vulnerability in Cisco Unified Communications Manager
Memory leak in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) allows remote attackers to cause a denial of service (memory consumption and service interruption) via a series of malformed TCP packets, as demonstrated by TCPFUZZ, aka Bug ID CSCsj80609.
network
low complexity
cisco CWE-399
7.8
2008-04-04 CVE-2008-1154 Improper Authentication vulnerability in Cisco products
The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5.x and 6.x, Unified Presence 1.x and 6.x, Emergency Responder 2.x, and Mobility Manager 2.x, does not require authentication for requests received from the network, which allows remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
cisco CWE-287
critical
10.0
2007-10-18 CVE-2007-5538 Buffer Errors vulnerability in Cisco products
Buffer overflow in the Centralized TFTP File Locator Service in Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(3), and Unified CallManager 5.0, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors involving the processing of filenames, aka CSCsh47712.
network
low complexity
cisco CWE-119
critical
10.0
2007-10-18 CVE-2007-5537 Resource Management Errors vulnerability in Cisco products
Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(2), and Unified CallManager 5.0, allow remote attackers to cause a denial of service (kernel panic) via a flood of SIP INVITE messages to UDP port 5060, which triggers resource exhaustion, aka CSCsi75822.
network
low complexity
cisco CWE-399
7.8
2007-08-09 CVE-2007-4294 Voice vulnerability in Cisco Unified Communications Manager 5.0/5.1/6.0
Unspecified vulnerability in Cisco Unified Communications Manager (CUCM) 5.0, 5.1, and 6.0, and IOS 12.0 through 12.4, allows remote attackers to execute arbitrary code via a malformed SIP packet, aka CSCsi80102.
network
cisco
6.8
2007-07-15 CVE-2006-5277 Heap Buffer Overflow vulnerability in Cisco products
Off-by-one error in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via a crafted packet that triggers a heap-based buffer overflow.
network
cisco
critical
9.3