
CVE-2015-0614
https://notcve.org/view.php?id=CVE-2015-0614
03 Apr 2015 — The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) via crafted SIP INVITE messages, aka Bug ID CSCul26267. El proceso Connection Conversation Manager (también conocido como CuCsMgr) en Cisco Unity Connection 8.5 anterior a 8.5(1)SU7, 8.6 anterior a 8.6(2a)SU4, 9.x ant... • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150401-cuc • CWE-19: Data Processing Errors •

CVE-2015-0615
https://notcve.org/view.php?id=CVE-2015-0615
03 Apr 2015 — The call-handling implementation in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (port consumption) by improperly terminating SIP sessions, aka Bug ID CSCul28089. La implementación call-handling en Cisco Unity Connection 8.5 anterior a 8.5(1)SU7, 8.6 anterior a 8.6(2a)SU4, 9.x anterior a 9.1(2)SU2, y 10.0 anterior a 10.0(1)SU1, cuando la integra... • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150401-cuc • CWE-19: Data Processing Errors •

CVE-2015-0616
https://notcve.org/view.php?id=CVE-2015-0616
03 Apr 2015 — The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, and 9.x before 9.1(2)SU2, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) by improperly terminating SIP TCP connections, aka Bug ID CSCul69819. El proceso Connection Conversation Manager (también conocido como CuCsMgr) en Cisco Unity Connection 8.5 anterior a 8.5(1)SU7, 8.6 anterior a 8.6(2a)SU4, y 9.x anterior a ... • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150401-cuc • CWE-19: Data Processing Errors •

CVE-2014-7988
https://notcve.org/view.php?id=CVE-2014-7988
07 Nov 2014 — The Unified Messaging Service (UMS) in Cisco Unity Connection 10.5 and earlier allows remote authenticated users to obtain sensitive information by reading log files, aka Bug ID CSCur06493. Unified Messaging Service (UMS) en Cisco Unity Connection 10.5 y anteriores permite a usuarios remotos autenticados obtener información sensible mediante la lectura de ficheros del registro, también conocido como Bug ID CSCur06493. • http://secunia.com/advisories/62106 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2014-3333
https://notcve.org/view.php?id=CVE-2014-3333
11 Aug 2014 — The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticated users to obtain privileged access by conducting an "HTTP Intercept" attack and leveraging the ability to read files within the context of the web-server user account, aka Bug ID CSCup41014. El servidor en Cisco Unity Connection 9.1(1) y 9.1(2) permite a usuarios remotos autenticados obtener el acceso privilegiado mediante la realización de un ataque de 'intercepción de HTTP' y el aprovechamiento de la habilidad de leer ficher... • http://secunia.com/advisories/59768 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2014-3336
https://notcve.org/view.php?id=CVE-2014-3336
11 Aug 2014 — SQL injection vulnerability in the web framework in Cisco Unity Connection 9.1(2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted request, aka Bug ID CSCuq31016. Vulnerabilidad de inyección SQL en el Framework web en Cisco Unity Connection 9.1(2) y anteriores permite a usuarios remotos autenticados ejecutar comandos SQL arbitrarios a través de una solicitud manipulada, también conocido como Bug ID CSCuq31016. • http://secunia.com/advisories/59498 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2014-2125
https://notcve.org/view.php?id=CVE-2014-2125
02 Apr 2014 — Cross-site scripting (XSS) vulnerability in the Web Inbox in Cisco Unity Connection 8.6(2a)SU3 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCui33028. Vulnerabilidad de XSS en Web Inbox de Cisco Unity Connection 8.6(2a)SU3 y anteriores permite a atacantes remotos inyectar script Web o HTML arbitrarios a través de un parámetro no especificado, también conocido como Bug ID CSCui33028. • http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2125 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2013-1129
https://notcve.org/view.php?id=CVE-2013-1129
19 Feb 2013 — Memory leak in Cisco Unity Connection 9.x allows remote attackers to cause a denial of service (memory consumption and process crash) by sending many TCP requests, aka Bug ID CSCud59736. Pérdida de memoria en Cisco Unity Connection v9.x que permite ataques remotos que provocan una denegación de servicios (consumo de memoria y caída de procesos) mediante el envío de muchas solicitudes TPC, ID del error CSCud59736. • http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1129 • CWE-399: Resource Management Errors •

CVE-2012-3060
https://notcve.org/view.php?id=CVE-2012-3060
16 Sep 2012 — Cisco Unity Connection (UC) 8.6, 9.0, and 9.5 allows remote attackers to cause a denial of service (CPU consumption) via malformed UDP packets, aka Bug ID CSCtz76269. Cisco Unity Connection (UC) v8.6, 9.0, y v9.5 permite a los atacantes remotos a provocar una denegación de servicio (consumo de CPU) a través de paquetes UDP manipulados también conocido como Bug ID CSCtz76269. • http://www.cisco.com/web/software/282074295/93949/cucm-readme-862asu2-Rev2.pdf • CWE-399: Resource Management Errors •

CVE-2012-3096
https://notcve.org/view.php?id=CVE-2012-3096
16 Sep 2012 — Cisco Unity Connection (UC) 7.1, 8.0, and 8.5 allows remote authenticated users to cause a denial of service (resource consumption and administration outage) via extended use of the product, aka Bug ID CSCtd79132. Cisco Unity Connection (UC) v7.1, v8.0, y v8.5 permite a usuarios remotos autenticados provocar una denegación de servicio (consumo de recursos y caída de administración) a través del uso extendido del producto, tambien conocido como Bug ID CSCtd79132. • http://www.cisco.com/en/US/docs/voice_ip_comm/connection/7x/release/notes/715cucrn.html •