Show filters
461 Total Results
Displaying 131-140 of 461
Sort by:
Attacker Value
Unknown

CVE-2021-25654

Disclosure Date: June 25, 2021 (last updated February 22, 2025)
An arbitrary code execution vulnerability was discovered in Avaya Aura Device Services that may potentially allow a local user to execute specially crafted scripts. Affects 7.0 through 8.1.4.0 versions of Avaya Aura Device Services.
Attacker Value
Unknown

CVE-2021-25655

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any untrusted site through a crafted attack. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).
Attacker Value
Unknown

CVE-2021-25656

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
Stored XSS injection vulnerabilities were discovered in the Avaya Aura Experience Portal Web management which could allow an authenticated user to potentially disclose sensitive information. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).
Attacker Value
Unknown

CVE-2021-25650

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to execute specially crafted scripts as a privileged user. Affects all 7.x versions of Avaya Aura Utility Services
Attacker Value
Unknown

CVE-2021-25651

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to escalate privileges. Affects all 7.x versions of Avaya Aura Utility Services
Attacker Value
Unknown

CVE-2021-25652

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Appliance Virtualization Platform Utilities (AVPU). This vulnerability may potentially allow any local user to access system functionality and configuration information that should only be available to a privileged user. Affects versions 8.0.0.0 through 8.1.3.1 of AVPU.
Attacker Value
Unknown

CVE-2021-25653

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
A privilege escalation vulnerability was discovered in Avaya Aura Appliance Virtualization Platform Utilities (AVPU) that may potentially allow a local user to escalate privileges. Affects 8.0.0.0 through 8.1.3.1 versions of AVPU.
Attacker Value
Unknown

CVE-2021-25649

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Utility Services. This vulnerability may potentially allow any local user to access system functionality and configuration information that should only be available to a privileged user. Affects all 7.x versions of Avaya Aura Utility Services
Attacker Value
Unknown

CVE-2021-3468

Disclosure Date: June 02, 2021 (last updated February 22, 2025)
A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.
Attacker Value
Unknown

CVE-2021-3502

Disclosure Date: May 07, 2021 (last updated February 22, 2025)
A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local attacker to crash the avahi service by requesting hostname resolutions through the avahi socket or dbus methods for invalid hostnames. The highest threat from this vulnerability is to the service availability.