Show filters
38 Total Results
Displaying 11-20 of 38
Sort by:
Attacker Value
Unknown

CVE-2010-3281

Disclosure Date: September 23, 2010 (last updated October 04, 2023)
Stack-based buffer overflow in the HTTP proxy service in Alcatel-Lucent OmniVista 4760 server before R5.1.06.03.c_Patch3 allows remote attackers to execute arbitrary code or cause a denial of service (service crash) via a long request.
0
Attacker Value
Unknown

CVE-2010-3279

Disclosure Date: September 23, 2010 (last updated October 04, 2023)
The default configuration of the CCAgent option before 9.0.8.4 in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition enables maintenance access, which allows remote attackers to monitor or reconfigure Contact Center operations via vectors involving TSA_maintenance.exe.
0
Attacker Value
Unknown

CVE-2010-3280

Disclosure Date: September 23, 2010 (last updated October 04, 2023)
The CCAgent option 9.0.8.4 and earlier in the management server (aka TSA) component in Alcatel-Lucent OmniTouch Contact Center Standard Edition relies on client-side authorization checking, and unconditionally sends the SuperUser password to the client for use during an authorized session, which allows remote attackers to monitor or reconfigure Contact Center operations via a modified client application.
0
Attacker Value
Unknown

CVE-2008-1331

Disclosure Date: April 02, 2008 (last updated October 04, 2023)
cgi-data/FastJSData.cgi in OmniPCX Office with Internet Access services OXO210 before 210/091.001, OXO600 before 610/014.001, and other versions, allows remote attackers to execute arbitrary commands and "obtain OXO resources" via shell metacharacters in the id2 parameter.
0
Attacker Value
Unknown

CVE-2007-5361

Disclosure Date: November 20, 2007 (last updated October 04, 2023)
The Communication Server in Alcatel-Lucent OmniPCX Enterprise 7.1 and earlier caches an IP address during a TFTP request from an IP Touch phone, and uses this IP address as the destination for all subsequent VoIP packets to this phone, which allows remote attackers to cause a denial of service (loss of audio) or intercept voice communications via a crafted TFTP request containing the phone's MAC address in the filename.
0
Attacker Value
Unknown

CVE-2007-5190

Disclosure Date: October 22, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Alcatel OmniVista 4760 R4.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the action parameter to php-bin/Webclient.php or (2) the Langue parameter to the default URI.
0
Attacker Value
Unknown

CVE-2007-2512

Disclosure Date: June 07, 2007 (last updated October 04, 2023)
Alcatel-Lucent IP-Touch Telephone running OmniPCX Enterprise 7.0 and later enables the mini switch by default, which allows attackers to gain access to the voice VLAN via daisy-chained systems.
0
Attacker Value
Unknown

CVE-2007-1822

Disclosure Date: April 02, 2007 (last updated October 04, 2023)
Alcatel-Lucent Lucent Technologies voice mail systems allow remote attackers to retrieve or remove messages, or reconfigure mailboxes, by spoofing Calling Number Identification (CNID, aka Caller ID).
0
Attacker Value
Unknown

CVE-2007-0931

Disclosure Date: February 14, 2007 (last updated October 04, 2023)
Heap-based buffer overflow in the management interfaces in (1) Aruba Mobility Controllers 200, 800, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via long credential strings.
0
Attacker Value
Unknown

CVE-2007-0932

Disclosure Date: February 14, 2007 (last updated October 04, 2023)
The (1) Aruba Mobility Controllers 200, 600, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 do not properly implement authentication and privilege assignment for the guest account, which allows remote attackers to access administrative interfaces or the WLAN.
0