12 results (0.004 seconds)

CVSS: 6.5EPSS: 0%CPEs: 18EXPL: 0

Unspecified vulnerability in Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allows remote authenticated users with read-only administrative privileges to obtain full administrative privileges via a "crafted URL on the CCMAdmin web page." • http://secunia.com/advisories/18501 http://securitytracker.com/id?1015502 http://www.cisco.com/warp/public/707/cisco-sa-20060118-ccmpe.shtml http://www.osvdb.org/22621 http://www.securityfocus.com/bid/16293 http://www.vupen.com/english/advisories/2006/0250 https://exchange.xforce.ibmcloud.com/vulnerabilities/24172 •

CVSS: 7.8EPSS: 6%CPEs: 23EXPL: 0

Cisco CallManager 3.2 and earlier, 3.3 before 3.3(5)SR1, 4.0 before 4.0(2a)SR2c, and 4.1 before 4.1(3)SR2 allow remote attackers to (1) cause a denial of service (CPU and memory consumption) via a large number of open TCP connections to port 2000 and (2) cause a denial of service (fill the Windows Service Manager communication queue) via a large number of TCP connections to port 2001, 2002, or 7727. • http://secunia.com/advisories/18494 http://securityreason.com/securityalert/359 http://securitytracker.com/id?1015503 http://www.cisco.com/warp/public/707/cisco-sa-20060118-ccmdos.shtml http://www.osvdb.org/22622 http://www.osvdb.org/22623 http://www.securityfocus.com/bid/16295 http://www.vupen.com/english/advisories/2006/0249 https://exchange.xforce.ibmcloud.com/vulnerabilities/24180 •

CVSS: 5.0EPSS: 0%CPEs: 4EXPL: 0

Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 does not quickly time out Realtime Information Server Data Collection (RISDC) sockets, which results in a "resource leak" that allows remote attackers to cause a denial of service (memory and connection consumption) in RisDC.exe. • http://www.cisco.com/warp/public/707/cisco-sa-20050712-ccm.shtml http://www.securityfocus.com/bid/14250 •

CVSS: 5.0EPSS: 2%CPEs: 4EXPL: 1

Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to cause a denial of service (memory consumption and restart) via crafted packets to (1) the CTI Manager (ctimgr.exe) or (2) the CallManager (ccm.exe). • https://www.exploit-db.com/exploits/25967 http://www.cisco.com/warp/public/707/cisco-sa-20050712-ccm.shtml http://www.securityfocus.com/bid/14251 http://www.securityfocus.com/bid/14252 •

CVSS: 5.0EPSS: 1%CPEs: 4EXPL: 0

The aupair service (aupair.exe) in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to execute arbitrary code or corrupt memory via crafted packets that trigger a memory allocation failure and lead to a buffer overflow. • http://www.cisco.com/warp/public/707/cisco-sa-20050712-ccm.shtml http://www.securityfocus.com/bid/14255 https://exchange.xforce.ibmcloud.com/vulnerabilities/19053 •