Vulnerabilities > Linksys > Spa941

DATE CVE VULNERABILITY TITLE RISK
2007-10-12 CVE-2007-5411 Cross-Site Scripting vulnerability in Linksys Spa941
Cross-site scripting (XSS) vulnerability in the Linksys SPA941 VoIP Phone with firmware 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the From header in a SIP message.
network
linksys CWE-79
4.3
2007-04-25 CVE-2007-2270 Denial of Service vulnerability in Linksys SPA941 377 Character
The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) character in the From header, and possibly certain other locations, in a SIP INVITE request.
network
low complexity
linksys
7.8