Cisco / Call Manager
18 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2007-5468 | Cisco CallManager 5.1.1.3000-5 does not verify the Digest authentication header URI against the Request URI in SIP messages, which allows remote attackers to u… | MEDIUM | 5.0 | Oct 16, 2007 |
| CVE-2007-4634 | Multiple SQL injection vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3… | HIGH | 9.3 | Aug 31, 2007 |
| CVE-2007-4633 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2… | MEDIUM | 4.3 | Aug 31, 2007 |
| CVE-2007-2832 | Cross-site scripting (XSS) vulnerability in the web application firewall in Cisco CallManager before 3.3(5)sr3, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and… | MEDIUM | 4.3 | May 24, 2007 |
| CVE-2007-1467 | Multiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch.html and (2) PreSearch.class in Cisco Secure Access Control Server (ACS), VPN Client, Unif… | LOW | 3.5 | Mar 16, 2007 |
| CVE-2006-3109 | Cross-site scripting (XSS) vulnerability in Cisco CallManager 3.3 before 3.3(5)SR3, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3), and 4.3 before 4.3(1), allows remo… | MEDIUM | 4.3 | Jun 21, 2006 |
| CVE-2006-0368 | Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allow remote attackers to (1) cause a denial of servi… | HIGH | 7.8 | Jan 22, 2006 |
| CVE-2006-0367 | Unspecified vulnerability in Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allows remote authentica… | MEDIUM | 6.5 | Jan 22, 2006 |
| CVE-2005-2244 | The aupair service (aupair.exe) in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remo… | MEDIUM | 5.0 | Jul 12, 2005 |
| CVE-2005-2243 | Memory leak in inetinfo.exe in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1, when Multi Lev… | MEDIUM | 5.0 | Jul 12, 2005 |
| CVE-2005-2241 | Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 does not quickly time out Realtime Information… | MEDIUM | 5.0 | Jul 12, 2005 |
| CVE-2005-0356 | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denia… | MEDIUM | 5.0 | May 31, 2005 |
| CVE-2004-1760 | The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which… | HIGH | 10.0 | Mar 10, 2005 |
| CVE-2004-1759 | Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumpt… | MEDIUM | 5.0 | Mar 10, 2005 |
| CVE-2004-0112 | security flaw | MEDIUM | 5.0 | Mar 18, 2004 |
| CVE-2004-0081 | security flaw | MEDIUM | 5.0 | Mar 18, 2004 |
| CVE-2004-0079 | security flaw | HIGH | 7.5 | Mar 18, 2004 |
| CVE-2002-0505 | Memory leak in the Call Telephony Integration (CTI) Framework authentication for Cisco CallManager 3.0 and 3.1 before 3.1(3) allows remote attackers to cause a… | MEDIUM | 5.0 | Apr 2, 2003 |
Showing 1 to 18 of 18 CVEs