3 results (0.008 seconds)

CVSS: 7.8EPSS: 0%CPEs: 20EXPL: 0

20 Sep 2015 — Buffer overflow in the Conference Control Protocol API implementation in Cisco TelePresence Server software before 4.1(2.33) on 7010, MSE 8710, Multiparty Media 310 and 320, and Virtual Machine devices allows remote attackers to cause a denial of service (device crash) via a crafted URL, aka Bug ID CSCuu28277. Desbordamiento de buffer en la implementación de la API del Conference Control Protocol en el software de Cisco TelePresence Server en versiones anteriores a 4.1(2.33) en 7010, MSE 8710, Multiparty Me... • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150916-tps • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 9.0EPSS: 0%CPEs: 42EXPL: 0

25 May 2015 — The web framework in Cisco TelePresence Advanced Media Gateway Series Software before 1.1(1.40), Cisco TelePresence IP Gateway Series Software, Cisco TelePresence IP VCR Series Software before 3.0(1.27), Cisco TelePresence ISDN Gateway Software before 2.2(1.94), Cisco TelePresence MCU Software before 4.4(3.54) and 4.5 before 4.5(1.45), Cisco TelePresence MSE Supervisor Software before 2.3(1.38), Cisco TelePresence Serial Gateway Series Software before 1.0(1.42), Cisco TelePresence Server Software for Hardwa... • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150513-tp • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 6.1EPSS: 0%CPEs: 4EXPL: 0

26 Jul 2014 — Multiple cross-site scripting (XSS) vulnerabilities in the login page in the administrative web interface in Cisco TelePresence Server Software 4.0(2.8) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCup90060. Múltiples vulnerabilidades de XSS en la página de inicio de sesión en la interfaz web administrativa en Cisco TelePresence Server Software 4.0(2.8) permiten a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de un pa... • http://secunia.com/advisories/60456 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •