Search: "avaya"

90 CVEs found

CVE-2001-1259
5.0 MEDIUM

Avaya Argent Office allows remote attackers to cause a denial of service by sending UDP packets to port 53 with no payload.

Published: 2001-08-07
Products: 1
Vendors:
avaya
CVE-2001-1260
10.0 HIGH

Avaya Argent Office uses weak encryption (trivial encoding) for passwords, which allows remote attackers to gain administrator privileges by sniffing and decrypting the sniffing the passwords during a...

Published: 2001-08-07
Products: 1
Vendors:
avaya
CVE-2001-1261
5.0 MEDIUM

Avaya Argent Office 2.1 may allow remote attackers to change hold music by spoofing a legitimate server's response to a TFTP broadcast and providing an alternate HoldMusic file.

Published: 2001-08-07
Products: 1
Vendors:
avaya

Avaya Argent Office 2.1 compares a user-provided SNMP community string with the correct string only up to the length of the user-provided string, which allows remote attackers to bypass authentication...

Published: 2001-08-07
Products: 1
Vendors:
avaya

An undocumented SNMP read/write community string ('NoGaH$@!') in Avaya P330, P130, and M770-ATM Cajun products allows remote attackers to gain administrative privileges.

Published: 2002-07-08
Products: 3
Vendors:
avaya

Avaya Cajun switches P880, P882, P580, and P550R 5.2.14 and earlier contain undocumented accounts (1) manuf and (2) diag with default passwords, which allows remote attackers to gain privileges.

Published: 2002-10-28
Products: 5
Vendors:
avaya
CVE-2005-0506
5.0 MEDIUM

The Avaya IP Office Phone Manager, and other products such as the IP Softphone, stores sensitive data in cleartext in a registry key, which allows local and possibly remote users to steal usernames an...

Published: 2005-03-14
Products: 2
Vendors:
avaya

Memory leak in Avaya TN2602AP IP Media Resource 320 circuit pack before vintage 9 firmware allows remote attackers to cause a denial of service (memory consumption) via crafted VoIP packets.

Published: 2005-12-04
Products: 6
Vendors:
avaya

Wireless Access Points (AP) for (1) Avaya AP-3 through AP-6 2.5 to 2.5.4, and AP-7/AP-8 2.5 and other versions before 3.1, and (2) Proxim AP-600 and AP-2000 before 2.5.5, and Proxim AP-700 and AP-4000...

Published: 2005-12-16
Products: 16
Vendors:
avaya proxim
CVE-2005-4471
5.0 MEDIUM

POP3 service in Avaya Modular Messaging Message Storage Server (MSS) 2.0 SP 4 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted packets.

Published: 2005-12-22
Products: 3
Vendors:
avaya

Avaya VPNRemote before 4.2.33 stores credentials in cleartext in process memory, which allows attackers to obtain the VPN user's credentials.

Published: 2005-12-31
Products: 6
Vendors:
avaya
CVE-2006-0718
5.0 MEDIUM

The Internet Key Exchange version 1 (IKEv1) implementation in Avaya VSU 100, 2000, 7500, 10000, and CSU 5000, when running IPSec, allows remote attackers to cause a denial of service (crash) via certa...

Published: 2006-02-15
Products: 5
Vendors:
avaya
CVE-2007-1367
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in the login page in Avaya Communications Manager (CM) S87XX, S8500, and S8300 products before 3.1.3 allows remote attackers to inject arbitrary web script or ...

Published: 2007-03-09
Products: 16
Vendors:
avaya
CVE-2007-1490
6.0 MEDIUM

Unspecified maintenance web pages in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allow remote authenticated users to execute arbitrary commands via shell metacharacters in unspecified...

Published: 2007-03-16
Products: 1
Vendors:
avaya
CVE-2007-1491
5.2 MEDIUM

Apache Tomcat in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allows connections from external interfaces via port 8009, which exposes it to attacks from outside parties.

Published: 2007-03-16
Products: 4
Vendors:
avaya

The Session Initiation Protocol (SIP) User Access Client (UAC) message parsing module in Avaya one-X Desktop Edition 2.1.0.70 and earlier allows remote attackers to cause a denial of service (device c...

Published: 2007-06-21
Products: 1
Vendors:
avaya
CVE-2007-3318
5.0 MEDIUM

Buffer overflow in the Session Initiation Protocol (SIP) User Access Client (UAC) message parsing module in Avaya one-X Desktop Edition 2.1.0.70 and earlier allows remote attackers to cause a denial o...

Published: 2007-06-21
Products: 1
Vendors:
avaya

The Avaya 4602SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware does not use the cnonce parameter in the Authorization header of SIP requests during MD5 digest authentication, which all...

Published: 2007-06-21
Products: 1
Vendors:
avaya
CVE-2007-3320
5.0 MEDIUM

The Avaya 4602SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware accepts SIP INVITE requests from arbitrary source IP addresses, which allows remote attackers to have an unspecified impa...

Published: 2007-06-21
Products: 1
Vendors:
avaya
CVE-2007-3321
5.0 MEDIUM

The Avaya 4602 SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware allows remote attackers to cause a denial of service (device reboot) via a flood of packets to the BOOTP port (68/udp).

Published: 2007-06-21
Products: 1
Vendors:
avaya