Vulnerability index

Browse CVEs

120 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2019-19608 A SQL injection vulnerability in in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated attack due to … Micollab Audio\, Web \& Video Conferencing after 8.1.1.11 Fix from $2,3002020-03-02 MEDIUM 6.1 CVE-2019-19370 A cross-site scripting (XSS) vulnerability in the web conferencing component of the Mitel MiCollab application before 9.0.15 for Android could allow … Micollab 9.0.15+ Fix from $1,6002020-03-02 MEDIUM 6.1 CVE-2019-19371 A cross-site scripting (XSS) vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unauthenticated atta… Micollab Audio\, Web \& Video Conferencing after 8.1.1.11 Fix from $1,6002020-03-02 MEDIUM 5.9 CVE-2019-18863 A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versions 5.1.0.2051 SP2 and earlie… 6863i Firmware 5.1.0.2051+ Fix from $1,6002020-03-02 MEDIUM 6.5 CVE-2020-9379 The Software Development Kit of the MiContact Center Business with Site Based Security 8.0 through 9.0.1.0 before KB496276 allows an authenticated us… Micontact Center Business after 9.0.1.0 Fix from $1,6002020-02-25 MEDIUM 5.9 CVE-2019-19891 An encryption key vulnerability on Mitel SIP-DECT wireless devices 8.0 and 8.1 could allow an attacker to launch a man-in-the-middle attack. A succes… Sip Dect Firmware Mitigation only Fix from $1,6002020-01-13 MEDIUM 5.3 CVE-2018-18819 A vulnerability in the web conference chat component of MiCollab, versions 7.3 PR6 (7.3.0.601) and earlier, and 8.0 (8.0.0.40) through 8.0 SP2 FP2 (8… Micollab after 8.0.2.202 Fix from $1,6002019-11-12 CRITICAL 9.8 CVE-2019-12165 MiCollab 7.3 PR2 (7.3.0.204) and earlier, 7.2 (7.2.2.13) and earlier, and 7.1 (7.1.0.57) and earlier and MiCollab AWV 6.3 (6.3.0.103), 6.2 (6.2.2.8),… Micollab after 7.3.0.204 Fix from $2,3002019-05-29 CRITICAL 9.8 CVE-2018-18285 SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to ins… Cmg Suite after 8.4 Fix from $2,3002019-04-25 CRITICAL 9.8 CVE-2018-18286 SQL injection vulnerabilities in CMG Suite 8.4 SP2 and earlier, could allow an unauthenticated attacker to conduct an SQL injection attack due to ins… Cmg Suite after 8.4 Fix from $2,3002019-04-25 CRITICAL 9.8 CVE-2018-19275 The BluStar component in Mitel InAttend before 2.5 SP3 and CMG before 8.4 SP3 Suite Servers has a default password, which could allow remote attacker… Cmg Suite 2.5 / 8.4+ Fix from $2,3002019-04-02 MEDIUM 6.1 CVE-2019-9591EPSS 5% A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attackers to inject arbitrary web s… Connect Onsite 19.49.1500.0+ Fix from $1,6002019-03-06 MEDIUM 6.1 CVE-2019-9592EPSS 5% A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to inject arbitrary web script o… Connect Onsite No fix yet Fix from $1,6002019-03-06 MEDIUM 6.1 CVE-2019-9593 A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to inject arbitrary web script o… Connect Onsite No fix yet Fix from $1,6002019-03-06 CRITICAL 9.8 CVE-2018-15497 The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality. An attacker can exploit this… Mivoice 5330e Firmware after 6.5.0.16 Fix from $2,3002018-10-23 MEDIUM 6.1 CVE-2018-12901 A vulnerability in the conferencing component of Mitel ST 14.2, versions GA29 (19.49.9400.0) and earlier, could allow an unauthenticated attacker to … St Firmware 19.49.9400.0+ Fix from $1,6002018-10-23 MEDIUM 6.1 CVE-2018-16226 A vulnerability in the web admin component of Mitel MiVoice Office 400, versions R5.0 HF3 (v8839a1) and earlier, could allow an unauthenticated attac… Mivoice Office 400 Mitigation only Fix from $1,6002018-10-23 HIGH 7.5 CVE-2016-6562 On iOS and Android devices, the ShoreTel Mobility Client app version 9.1.3.109 fails to properly validate SSL certificates provided by HTTPS connecti… Shortel Mobility Client Mitigation only Fix from $1,9502018-07-13 MEDIUM 6.5 CVE-2018-9102 A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versio… Mivoice Connect after 21.84.5535.0 Fix from $1,6002018-04-25 MEDIUM 6.1 CVE-2018-9101 A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versio… Mivoice Connect after 21.84.5535.0 Fix from $1,6002018-04-25 MEDIUM 6.1 CVE-2018-9103 A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versio… Mivoice Connect after 21.84.5535.0 Fix from $1,6002018-04-25 MEDIUM 6.1 CVE-2018-9104 A vulnerability in the conferencing component of Mitel MiVoice Connect, versions R1707-PREM SP1 (21.84.5535.0) and earlier, and Mitel ST 14.2, versio… Mivoice Connect after 21.84.5535.0 Fix from $1,6002018-04-25 CRITICAL 9.8 CVE-2018-5779 A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, … Connect Onsite Mitigation only Fix from $2,3002018-03-14 CRITICAL 9.8 CVE-2018-5780 A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, … Connect Onsite Mitigation only Fix from $2,3002018-03-14 CRITICAL 9.8 CVE-2018-5781 A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, … Connect Onsite Mitigation only Fix from $2,3002018-03-14 CRITICAL 9.8 CVE-2018-5782EPSS 19% A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, … Connect Onsite No fix yet Fix from $2,3002018-03-14 HIGH 8.8 CVE-2017-16251 A vulnerability in the conferencing component of Mitel ST 14.2, release GA28 and earlier, could allow an authenticated user to upload a malicious scr… St14.2 Mitigation only Fix from $1,9502018-03-13 MEDIUM 5.3 CVE-2017-16250 A vulnerability in Mitel ST 14.2, release GA28 and earlier, could allow an attacker to use the API function to enumerate through user-ids which could… St14.2 Mitigation only Fix from $1,6002018-03-13 HIGH 7.8 CVE-2008-6797 The server in Mitel NuPoint Messenger R11 and R3 sends usernames and passwords in cleartext to Exchange servers, which allows remote attackers to obt… Mitel Nupoint Messenger Mitigation only Fix from $1,9502009-05-07 MEDIUM 5.0 CVE-2004-0945 The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 allows remote authenticated users to cause a den… Mitel 3300 Integrated Communication Platform Mitigation only Fix from $1,6002005-02-28