Vulnerability index

Browse CVEs

100 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Communication Manager HIGH 7.5
CVE-2008-6574

Unspecified vulnerability in SIP Enablement Services (SES) in Avaya Communication Manager 3.1.x and 4.x allows remote attackers to gain privileges an…

Mitigation only
Fix from $1,950 2009-04-01
Communication Manager MEDIUM 6.8
CVE-2008-6575

Unspecified vulnerability in the SIP server in SIP Enablement Services (SES) in Avaya Communication Manager 3.1.x and 4.x allows remote authenticated…

Mitigation only
Fix from $1,600 2009-04-01
Communication Manager MEDIUM 6.8
CVE-2008-6573

Multiple SQL injection vulnerabilities in Avaya SIP Enablement Services (SES) in Avaya Avaya Communication Manager 3.x, 4.0, and 5.0 (1) allow remote…

Fix: after 3.1
Fix from $1,600 2009-04-01
One X MEDIUM 5.0
CVE-2008-6140

Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Avaya one-X Desktop Edition 2.1.0.78 allows remote attackers to …

No fix yet
Fix from $1,600 2009-02-14
Ip Soft Phone MEDIUM 5.0
CVE-2008-6141

Unspecified vulnerability in Avaya IP Softphone 6.0 SP4 and 6.01.85 allows remote attackers to cause a denial of service (crash) via a large amount o…

Mitigation only
Fix from $1,600 2009-02-14
Communication Manager HIGH 9.0
CVE-2008-5709

Multiple unspecified vulnerabilities in the web management interface in Avaya Communication Manager (CM) 3.1 before 3.1.4 SP2, 4.0 before 4.0.3 SP1, …

Mitigation only
Fix from $1,950 2008-12-24
Communication Manager MEDIUM 5.0
CVE-2008-5710

Multiple unspecified vulnerabilities in the web management interface in Avaya Communication Manager (CM) 3.1.x, 4.0.3, and 5.x allow remote attackers…

No fix yet
Fix from $1,600 2008-12-24
Sip Enablement Services HIGH 7.5
CVE-2008-3778

The remote management interface in SIP Enablement Services (SES) Server in Avaya SIP Enablement Services 5.0, and Communication Manager (CM) 5.0 on t…

Mitigation only
Fix from $1,950 2008-08-25
Messaging Storage Server MEDIUM 6.5
CVE-2008-3081

Multiple unspecified "input validation" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Sto…

Mitigation only
Fix from $1,600 2008-07-09
Message Networking HIGH 7.8
CVE-2007-5830

Unspecified vulnerability in the administrative interface in Avaya Messaging Storage Server (MSS) 3.1 before SP1, and Message Networking (MN) 3.1, al…

Patch available
Fix from $1,950 2007-11-05
Voip Handset HIGH 7.8
CVE-2007-5556

Unspecified vulnerability in the Avaya VoIP Handset allows remote attackers to cause a denial of service (reboot) via crafted packets. NOTE: as of 20…

No fix yet
Fix from $1,950 2007-10-18
Ip Soft Phone MEDIUM 6.8
CVE-2007-3286

Multiple buffer overflows in unspecified ActiveX controls in COM objects in Avaya IP Softphone R5.2 before SP3, and R6.0, allow remote attackers to e…

Fix: after 5.2
Fix from $1,600 2007-09-19
One X HIGH 7.8
CVE-2007-3317

The Session Initiation Protocol (SIP) User Access Client (UAC) message parsing module in Avaya one-X Desktop Edition 2.1.0.70 and earlier allows remo…

Fix: after 2.1.0.70
Fix from $1,950 2007-06-21
4602sw Ip Phone HIGH 7.5
CVE-2007-3319

The Avaya 4602SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware does not use the cnonce parameter in the Authorization header of SIP r…

Mitigation only
Fix from $1,950 2007-06-21
One X MEDIUM 5.0
CVE-2007-3318

Buffer overflow in the Session Initiation Protocol (SIP) User Access Client (UAC) message parsing module in Avaya one-X Desktop Edition 2.1.0.70 and …

Fix: after 2.1.0.70
Fix from $1,600 2007-06-21
4602sw Ip Phone MEDIUM 5.0
CVE-2007-3320

The Avaya 4602SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware accepts SIP INVITE requests from arbitrary source IP addresses, which …

Mitigation only
Fix from $1,600 2007-06-21
4602sw Ip Phone MEDIUM 5.0
CVE-2007-3321

The Avaya 4602 SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware allows remote attackers to cause a denial of service (device reboot) …

Mitigation only
Fix from $1,600 2007-06-21
4602sw Ip Phone MEDIUM 5.0
CVE-2007-3322

The Avaya 4602 SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware uses a constant media port number for calls, which allows remote atta…

Mitigation only
Fix from $1,600 2007-06-21
Communication Manager MEDIUM 6.0
CVE-2007-1490

Unspecified maintenance web pages in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allow remote authenticated users to execute arbitra…

Fix: after 3.1.3
Fix from $1,600 2007-03-16
Sip Enablement Services MEDIUM 5.2
CVE-2007-1491

Apache Tomcat in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allows connections from external interfaces via port 8009, which expose…

Mitigation only
Fix from $1,600 2007-03-16
Vsu 100 MEDIUM 5.0
CVE-2006-0718

The Internet Key Exchange version 1 (IKEv1) implementation in Avaya VSU 100, 2000, 7500, 10000, and CSU 5000, when running IPSec, allows remote attac…

Patch available
Fix from $1,600 2006-02-15
Modular Messaging Message Storage Server MEDIUM 5.0
CVE-2005-4471

POP3 service in Avaya Modular Messaging Message Storage Server (MSS) 2.0 SP 4 and earlier allows remote attackers to cause a denial of service (infin…

Fix: after 2.0_sp_4
Fix from $1,600 2005-12-22
Wireless Ap 3 HIGH 7.5
CVE-2005-3253

Wireless Access Points (AP) for (1) Avaya AP-3 through AP-6 2.5 to 2.5.4, and AP-7/AP-8 2.5 and other versions before 3.1, and (2) Proxim AP-600 and …

Patch available
Fix from $1,950 2005-12-16
Tn2602ap Ip Media Resource 320 Circuit Pack HIGH 7.8
CVE-2005-3989

Memory leak in Avaya TN2602AP IP Media Resource 320 circuit pack before vintage 9 firmware allows remote attackers to cause a denial of service (memo…

Patch available
Fix from $1,950 2005-12-04
Libsafe MEDIUM 5.1
CVE-2005-1125EPSS 7%

Race condition in libsafe 2.0.16 and earlier, when running in multi-threaded applications, allows attackers to bypass libsafe protection and exploit …

No fix yet
Fix from $1,600 2005-05-02
Ip Office Phone Manager MEDIUM 5.0
CVE-2005-0506

The Avaya IP Office Phone Manager, and other products such as the IP Softphone, stores sensitive data in cleartext in a registry key, which allows lo…

Mitigation only
Fix from $1,600 2005-03-14
Ip600 Media Servers HIGH 10.0
CVE-2004-1050EPSS 67%

Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME…

Mitigation only
Fix from $1,950 2004-12-31
Ip600 Media Servers HIGH 7.5
CVE-2004-0842EPSS 57%

Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "mem…

Patch available
Fix from $1,950 2004-12-23
Ip600 Media Servers MEDIUM 5.0
CVE-2004-0841EPSS 49%

Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-dro…

Patch available
Fix from $1,600 2004-12-23
Ip600 Media Servers MEDIUM 5.0
CVE-2004-0839EPSS 34%

Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page …

Patch available
Fix from $1,600 2004-08-18