Vulnerabilities > Cisco > Unified Communications Manager

DATE CVE VULNERABILITY TITLE RISK
2008-06-26 CVE-2008-2061 Improper Input Validation vulnerability in Cisco Unified Communications Manager
The Computer Telephony Integration (CTI) Manager service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3c) and 6.x before 6.1(2) allows remote attackers to cause a denial of service (TSP crash) via malformed network traffic to TCP port 2748.
network
low complexity
cisco CWE-20
7.8
2008-05-16 CVE-2008-1748 Improper Input Validation vulnerability in Cisco Unified Communications Manager
Cisco Unified Communications Manager 4.1 before 4.1(3)SR7, 4.2 before 4.2(3)SR4, 4.3 before 4.3(2), 5.x before 5.1(3), and 6.x before 6.1(1) does not properly validate SIP URLs, which allows remote attackers to cause a denial of service (service interruption) via a SIP INVITE message, aka Bug ID CSCsl22355.
network
low complexity
cisco CWE-20
7.8
2008-05-16 CVE-2008-1747 Improper Input Validation vulnerability in Cisco Unified Communications Manager
Unspecified vulnerability in Cisco Unified Communications Manager 4.1 before 4.1(3)SR6, 4.2 before 4.2(3)SR3, 4.3 before 4.3(2), 5.x before 5.1(3), and 6.x before 6.1(1) allows remote attackers to cause a denial of service (CCM service restart) via an unspecified SIP INVITE message, aka Bug ID CSCsk46944.
network
low complexity
cisco CWE-20
7.8
2008-05-16 CVE-2008-1746 Improper Input Validation vulnerability in Cisco Unified Communications Manager
The SNMP Trap Agent service in Cisco Unified Communications Manager (CUCM) 4.1 before 4.1(3)SR6, 4.2 before 4.2(3)SR3, 4.3 before 4.3(2), 5.x before 5.1(3), and 6.x before 6.1(1) allows remote attackers to cause a denial of service (core dump and service restart) via a series of malformed UDP packets, as demonstrated by the IP Stack Integrity Checker (ISIC), aka Bug ID CSCsj24113.
network
low complexity
cisco CWE-20
7.8
2008-05-16 CVE-2008-1745 Improper Input Validation vulnerability in Cisco Unified Communications Manager
Cisco Unified Communications Manager (CUCM) 5.x before 5.1(2) and 6.x before 6.1(1) allows remote attackers to cause a denial of service (service interruption) via a SIP JOIN message with a malformed header, aka Bug ID CSCsi48115.
network
low complexity
cisco CWE-20
7.8
2008-05-16 CVE-2008-1744 Improper Input Validation vulnerability in Cisco products
The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager (CUCM) 4.1 before 4.1(3)SR7, 4.2 before 4.2(3)SR4, and 4.3 before 4.3(2) allows remote attackers to cause a denial of service (service crash) via malformed network traffic, aka Bug ID CSCsk46770.
network
low complexity
cisco CWE-20
7.8
2008-05-16 CVE-2008-1743 Resource Management Errors vulnerability in Cisco Unified Communications Manager
Memory leak in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) and 6.x before 6.1(1) allows remote attackers to cause a denial of service (memory consumption and service interruption) via a series of malformed TCP packets, aka Bug ID CSCsi98433.
network
low complexity
cisco CWE-399
7.8
2008-05-16 CVE-2008-1742 Resource Management Errors vulnerability in Cisco Unified Communications Manager
Memory leak in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) allows remote attackers to cause a denial of service (memory consumption and service interruption) via a series of malformed TCP packets, as demonstrated by TCPFUZZ, aka Bug ID CSCsj80609.
network
low complexity
cisco CWE-399
7.8
2008-04-04 CVE-2008-1154 Improper Authentication vulnerability in Cisco products
The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5.x and 6.x, Unified Presence 1.x and 6.x, Emergency Responder 2.x, and Mobility Manager 2.x, does not require authentication for requests received from the network, which allows remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
cisco CWE-287
critical
10.0
2008-02-14 CVE-2008-0026 SQL Injection vulnerability in Cisco products
SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6.1(1a) allows remote authenticated users to execute arbitrary SQL commands via the key parameter to the (1) admin and (2) user interface pages.
network
low complexity
cisco CWE-89
6.5