Show filters
320 Total Results
Displaying 211-220 of 320
Sort by:
Attacker Value
Unknown
CVE-2014-0664
Disclosure Date: January 10, 2014 (last updated October 05, 2023)
The server in Cisco Unity Connection allows remote authenticated users to cause a denial of service (CPU consumption) via unspecified IMAP commands, aka Bug ID CSCul49976.
0
Attacker Value
Unknown
CVE-2012-4529
Disclosure Date: October 28, 2013 (last updated October 05, 2023)
The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain the session id (1) via a man-in-the-middle attack or (2) by reading a log.
0
Attacker Value
Unknown
CVE-2013-5534
Disclosure Date: October 19, 2013 (last updated October 05, 2023)
Directory traversal vulnerability in the attachment service in the Voice Message Web Service (aka VMWS or Cisco Unity Web Service) in Cisco Unity Connection allows remote authenticated users to create files, and consequently execute arbitrary JSP code, via a crafted pathname for a file that is not a valid audio file, aka Bug ID CSCuj22948.
0
Attacker Value
Unknown
CVE-2013-1055
Disclosure Date: May 02, 2013 (last updated February 22, 2025)
The unity-firefox-extension package could be tricked into dropping a C callback which was still in use, which Firefox would then free, causing Firefox to crash. This could be achieved by adding an action to the launcher and updating it with new callbacks until the libunity-webapps rate limit was hit. Fixed in 3.0.0+14.04.20140416-0ubuntu1.14.04.1 of unity-firefox-extension and in all versions of libunity-webapps by shipping an empty unity-firefox-extension package, thus disabling the extension entirely and invalidating the attack against the libunity-webapps package.
0
Attacker Value
Unknown
CVE-2013-1054
Disclosure Date: May 02, 2013 (last updated February 22, 2025)
The unity-firefox-extension package could be tricked into destroying the Unity webapps context, causing Firefox to crash. This could be achieved by spinning the event loop inside the webapps initialization callback. Fixed in 3.0.0+14.04.20140416-0ubuntu1.14.04.1 by shipping an empty package, thus disabling the extension entirely.
0
Attacker Value
Unknown
CVE-2013-1129
Disclosure Date: February 19, 2013 (last updated October 05, 2023)
Memory leak in Cisco Unity Connection 9.x allows remote attackers to cause a denial of service (memory consumption and process crash) by sending many TCP requests, aka Bug ID CSCud59736.
0
Attacker Value
Unknown
CVE-2013-1114
Disclosure Date: February 13, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unity Express before 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCud87527.
0
Attacker Value
Unknown
CVE-2013-1120
Disclosure Date: February 06, 2013 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Unity Express with software before 8.0 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCue35910.
0
Attacker Value
Unknown
CVE-2012-0958
Disclosure Date: December 26, 2012 (last updated October 05, 2023)
content/unity-api.js in the unity-firefox-extension extension 2.4.1 for Firefox exposes the toDataURL function in an API call, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted webpage.
0
Attacker Value
Unknown
CVE-2012-4551
Disclosure Date: November 30, 2012 (last updated October 05, 2023)
Use-after-free vulnerability in libunity-webapps before 2.4.1 allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via a crafted web site, related to "certain hash tables."
0