Show filters
137 Total Results
Displaying 91-100 of 137
Sort by:
Attacker Value
Unknown

CVE-2007-3319

Disclosure Date: June 21, 2007 (last updated October 04, 2023)
The Avaya 4602SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware does not use the cnonce parameter in the Authorization header of SIP requests during MD5 digest authentication, which allows remote attackers to conduct man-in-the-middle attacks and hijack or intercept communications.
0
Attacker Value
Unknown

CVE-2007-3318

Disclosure Date: June 21, 2007 (last updated October 04, 2023)
Buffer overflow in the Session Initiation Protocol (SIP) User Access Client (UAC) message parsing module in Avaya one-X Desktop Edition 2.1.0.70 and earlier allows remote attackers to cause a denial of service (call reception outage) via a malformed SIP message.
0
Attacker Value
Unknown

CVE-2007-2374

Disclosure Date: April 30, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Microsoft Windows 2000, XP, and Server 2003 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors. NOTE: this information is based upon a vague pre-advisory with no actionable information. However, the advisory is from a reliable source.
0
Attacker Value
Unknown

CVE-2007-1765

Disclosure Date: March 30, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this issue might be a duplicate of CVE-2007-0038; if so, then use CVE-2007-0038 instead of this identifier.
0
Attacker Value
Unknown

CVE-2007-1490

Disclosure Date: March 16, 2007 (last updated October 04, 2023)
Unspecified maintenance web pages in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allow remote authenticated users to execute arbitrary commands via shell metacharacters in unspecified vectors (aka "shell command injection").
0
Attacker Value
Unknown

CVE-2007-1491

Disclosure Date: March 16, 2007 (last updated October 04, 2023)
Apache Tomcat in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allows connections from external interfaces via port 8009, which exposes it to attacks from outside parties.
0
Attacker Value
Unknown

CVE-2007-1367

Disclosure Date: March 09, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the login page in Avaya Communications Manager (CM) S87XX, S8500, and S8300 products before 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the Login field.
0
Attacker Value
Unknown

CVE-2006-1058

Disclosure Date: April 04, 2006 (last updated February 22, 2025)
BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.
Attacker Value
Unknown

CVE-2006-0718

Disclosure Date: February 15, 2006 (last updated February 22, 2025)
The Internet Key Exchange version 1 (IKEv1) implementation in Avaya VSU 100, 2000, 7500, 10000, and CSU 5000, when running IPSec, allows remote attackers to cause a denial of service (crash) via certain IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.
0
Attacker Value
Unknown

CVE-2005-2762

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Avaya VPNRemote before 4.2.33 stores credentials in cleartext in process memory, which allows attackers to obtain the VPN user's credentials.
0