Vulnerability index

Browse CVEs

120 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Micollab Audio\, Web \& Video Conferencing CRITICAL 9.8
CVE-2019-19608

A SQL injection vulnerability in in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attack due to …

Fix: after 8.1.1.11
Fix from $2,300 2020-03-02
Micollab MEDIUM 6.1
CVE-2019-19370

A cross-site scripting (XSS) vulnerability in the web conferencing component of the Mitel MiCollab application before 9.0.15 for Android could allow …

Fix: 9.0.15+
Fix from $1,600 2020-03-02
Micollab Audio\, Web \& Video Conferencing MEDIUM 6.1
CVE-2019-19371

A cross-site scripting (XSS) vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated atta…

Fix: after 8.1.1.11
Fix from $1,600 2020-03-02
6863i Firmware MEDIUM 5.9
CVE-2019-18863

A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versions 5.1.0.2051 SP2 and earlie…

Fix: 5.1.0.2051+
Fix from $1,600 2020-03-02
Micontact Center Business MEDIUM 6.5
CVE-2020-9379

The Software Development Kit of the MiContact Center Business with Site Based Security 8.0 through 9.0.1.0 before KB496276 allows an authenticated us…

Fix: after 9.0.1.0
Fix from $1,600 2020-02-25
Sip Dect Firmware MEDIUM 5.9
CVE-2019-19891

An encryption key vulnerability on Mitel SIP-DECT wireless devices 8.0 and 8.1 could allow an attacker to launch a man-in-the-middle attack. A succes…

Mitigation only
Fix from $1,600 2020-01-13
Micollab MEDIUM 5.3
CVE-2018-18819

A vulnerability in the web conference chat component of MiCollab, versions 7.3 PR6 (7.3.0.601) and earlier, and 8.0 (8.0.0.40) through 8.0 SP2 FP2 (8…

Fix: after 8.0.2.202
Fix from $1,600 2019-11-12
Micollab CRITICAL 9.8
CVE-2019-12165

MiCollab 7.3 PR2 (7.3.0.204) and earlier, 7.2 (7.2.2.13) and earlier, and 7.1 (7.1.0.57) and earlier and MiCollab AWV 6.3 (6.3.0.103), 6.2 (6.2.2.8),…

Fix: after 7.3.0.204
Fix from $2,300 2019-05-29
Cmg Suite CRITICAL 9.8
CVE-2018-18285

SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to ins…

Fix: after 8.4
Fix from $2,300 2019-04-25
Cmg Suite CRITICAL 9.8
CVE-2018-18286

SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to ins…

Fix: after 8.4
Fix from $2,300 2019-04-25
Cmg Suite CRITICAL 9.8
CVE-2018-19275

The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remote attacker…

Fix: 2.5 / 8.4+
Fix from $2,300 2019-04-02
Connect Onsite MEDIUM 6.1
CVE-2019-9591EPSS 5%

A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject arbitrary web s…

Fix: 19.49.1500.0+
Fix from $1,600 2019-03-06
Connect Onsite MEDIUM 6.1
CVE-2019-9592EPSS 5%

A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to inject arbitrary web script o…

No fix yet
Fix from $1,600 2019-03-06
Connect Onsite MEDIUM 6.1
CVE-2019-9593

A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to inject arbitrary web script o…

No fix yet
Fix from $1,600 2019-03-06
Mivoice 5330e Firmware CRITICAL 9.8
CVE-2018-15497

The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality. An attacker can exploit this…

Fix: after 6.5.0.16
Fix from $2,300 2018-10-23
St Firmware MEDIUM 6.1
CVE-2018-12901

A vulnerability in the conferencing component of Mitel ST 14.2, versions GA29 (19.49.9400.0) and earlier, could allow an unauthenticated attacker to …

Fix: 19.49.9400.0+
Fix from $1,600 2018-10-23
Mivoice Office 400 MEDIUM 6.1
CVE-2018-16226

A vulnerability in the web admin component of Mitel MiVoice Office 400, versions R5.0 HF3 (v8839a1) and earlier, could allow an unauthenticated attac…

Mitigation only
Fix from $1,600 2018-10-23
Shortel Mobility Client HIGH 7.5
CVE-2016-6562

On iOS and Android devices, the ShoreTel Mobility Client app version 9.1.3.109 fails to properly validate SSL certificates provided by HTTPS connecti…

Mitigation only
Fix from $1,950 2018-07-13
Mivoice Connect MEDIUM 6.5
CVE-2018-9102

A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versio…

Fix: after 21.84.5535.0
Fix from $1,600 2018-04-25
Mivoice Connect MEDIUM 6.1
CVE-2018-9101

A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versio…

Fix: after 21.84.5535.0
Fix from $1,600 2018-04-25
Mivoice Connect MEDIUM 6.1
CVE-2018-9103

A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versio…

Fix: after 21.84.5535.0
Fix from $1,600 2018-04-25
Mivoice Connect MEDIUM 6.1
CVE-2018-9104

A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versio…

Fix: after 21.84.5535.0
Fix from $1,600 2018-04-25
Connect Onsite CRITICAL 9.8
CVE-2018-5779

A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, …

Mitigation only
Fix from $2,300 2018-03-14
Connect Onsite CRITICAL 9.8
CVE-2018-5780

A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, …

Mitigation only
Fix from $2,300 2018-03-14
Connect Onsite CRITICAL 9.8
CVE-2018-5781

A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, …

Mitigation only
Fix from $2,300 2018-03-14
Connect Onsite CRITICAL 9.8
CVE-2018-5782EPSS 19%

A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, …

No fix yet
Fix from $2,300 2018-03-14
St14.2 HIGH 8.8
CVE-2017-16251

A vulnerability in the conferencing component of Mitel ST 14.2, release GA28 and earlier, could allow an authenticated user to upload a malicious scr…

Mitigation only
Fix from $1,950 2018-03-13
St14.2 MEDIUM 5.3
CVE-2017-16250

A vulnerability in Mitel ST 14.2, release GA28 and earlier, could allow an attacker to use the API function to enumerate through user-ids which could…

Mitigation only
Fix from $1,600 2018-03-13
Mitel Nupoint Messenger HIGH 7.8
CVE-2008-6797

The server in Mitel NuPoint Messenger R11 and R3 sends usernames and passwords in cleartext to Exchange servers, which allows remote attackers to obt…

Mitigation only
Fix from $1,950 2009-05-07
Mitel 3300 Integrated Communication Platform MEDIUM 5.0
CVE-2004-0945

The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 allows remote authenticated users to cause a den…

Mitigation only
Fix from $1,600 2005-02-28