3 results (0.003 seconds)

CVSS: 7.8EPSS: 2%CPEs: 46EXPL: 0

Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 5.x before 5.1(3g), 6.x before 6.1(4), 7.0.x before 7.0(2a)su1, and 7.1.x before 7.1(2) allows remote attackers to cause a denial of service (service restart) via malformed SIP messages, aka Bug ID CSCsz95423. Cisco Unified Communications Manager (también conocido como CUCM, antiguamente como CallManager) v5.x anterior a v5.1(3g), v6.x anterior a v6.1(4), v7.0.x anterior a v7.0(2a)su1 y v7.1.x anterior a v7.1(2) permite a usuarios remotos provocar una denegación del servicio (reinicio del servicio) a través de mensajes SIP malformados. También conocido como Bug ID CSCsz95423. • http://osvdb.org/58344 http://secunia.com/advisories/36836 http://tools.cisco.com/security/center/viewAlert.x?alertId=18883 http://www.cisco.com/en/US/products/products_security_advisory09186a0080af8118.shtml http://www.securityfocus.com/bid/36496 http://www.securitytracker.com/id?1022931 http://www.vupen.com/english/advisories/2009/2757 https://exchange.xforce.ibmcloud.com/vulnerabilities/53447 •

CVSS: 7.8EPSS: 2%CPEs: 20EXPL: 0

The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager (CUCM) 4.1 before 4.1(3)SR7, 4.2 before 4.2(3)SR4, and 4.3 before 4.3(2) allows remote attackers to cause a denial of service (service crash) via malformed network traffic, aka Bug ID CSCsk46770. El servicio Certificate Authority Proxy Function (CAPF) service de Cisco Unified Communications Manager (CUCM) 4.1 versiones anteriores a 4.1(3)SR7, 4.2 versiones anteriores a 4.2(3)SR4, y 4.3 versiones anteriores a 4.3(2) permite a atacantes remotos provocar una denegación de servicio (caída del servicio) a través de tráfico de red malformado, también conocido como Bug ID CSCsk46770. • http://secunia.com/advisories/30238 http://securitytracker.com/id?1020022 http://www.cisco.com/en/US/products/products_security_advisory09186a0080995688.shtml http://www.securityfocus.com/bid/29221 http://www.vupen.com/english/advisories/2008/1533 https://exchange.xforce.ibmcloud.com/vulnerabilities/42415 • CWE-20: Improper Input Validation •

CVSS: 6.5EPSS: 0%CPEs: 20EXPL: 1

SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6.1(1a) allows remote authenticated users to execute arbitrary SQL commands via the key parameter to the (1) admin and (2) user interface pages. Una vulnerabilidad de la inyección SQL en Cisco Unified CallManager/Communications Manager (CUCM) versiones 5.0/5.1 anteriores a 5.1(3a) y versiones 6.0/6.1 anteriores a 6.1(1a), permite a los usuarios autenticados remotos ejecutar comandos SQL arbitrarios por medio del parámetro key en las páginas de interfaz de (1) administrador y (2) usuario. • https://www.exploit-db.com/exploits/31189 http://secunia.com/advisories/28932 http://www.cisco.com/en/US/products/products_security_advisory09186a0080949c7c.shtml http://www.securityfocus.com/bid/27775 http://www.securitytracker.com/id?1019404 http://www.vupen.com/english/advisories/2008/0542 https://exchange.xforce.ibmcloud.com/vulnerabilities/40484 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •