Skip to main content

Vendor archive

avaya CVEs

Beta · best-effort

139 CVEs tagged to vendor avaya22 Critical, 52 High, 61 Medium, 4 Low, 0 Unrated.

CVE-2009-0115

Published Mar 30, 2009

The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly o…

CVSS 7.8 · High

CVE-2008-6141

Published Feb 14, 2009

Unspecified vulnerability in Avaya IP Softphone 6.0 SP4 and 6.01.85 allows remote attackers to cause a denial of service (crash) via a large amount of H.323 data.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6140

Published Feb 14, 2009

Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Avaya one-X Desktop Edition 2.1.0.78 allows remote attackers to cause a denial of service (cra…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5710

Published Dec 24, 2008

Multiple unspecified vulnerabilities in the web management interface in Avaya Communication Manager (CM) 3.1.x, 4.0.3, and 5.x allow remote attackers to read (1) configuration fil…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5709

Published Dec 24, 2008

Multiple unspecified vulnerabilities in the web management interface in Avaya Communication Manager (CM) 3.1 before 3.1.4 SP2, 4.0 before 4.0.3 SP1, and 5.0 before 5.0 SP3 allow r…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-3081

Published Jul 9, 2008

Multiple unspecified "input validation" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Storage Server (MSS) 3.x and 4.0,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5556

Published Oct 18, 2007

Unspecified vulnerability in the Avaya VoIP Handset allows remote attackers to cause a denial of service (reboot) via crafted packets. NOTE: as of 20071016, the only disclosure is…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3286

Published Sep 19, 2007

Multiple buffer overflows in unspecified ActiveX controls in COM objects in Avaya IP Softphone R5.2 before SP3, and R6.0, allow remote attackers to execute arbitrary code via unsp…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3317

Published Jun 21, 2007

The Session Initiation Protocol (SIP) User Access Client (UAC) message parsing module in Avaya one-X Desktop Edition 2.1.0.70 and earlier allows remote attackers to cause a denial…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3318

Published Jun 21, 2007

Buffer overflow in the Session Initiation Protocol (SIP) User Access Client (UAC) message parsing module in Avaya one-X Desktop Edition 2.1.0.70 and earlier allows remote attacker…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3319

Published Jun 21, 2007

The Avaya 4602SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware does not use the cnonce parameter in the Authorization header of SIP requests during MD5 digest auth…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3320

Published Jun 21, 2007

The Avaya 4602SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware accepts SIP INVITE requests from arbitrary source IP addresses, which allows remote attackers to hav…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3321

Published Jun 21, 2007

The Avaya 4602 SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware allows remote attackers to cause a denial of service (device reboot) via a flood of packets to the…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3322

Published Jun 21, 2007

The Avaya 4602 SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware uses a constant media port number for calls, which allows remote attackers to cause a denial of ser…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1765

Published Mar 30, 2007

Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malf…

CVSS 9.3 · Critical

CVE-2007-1490

Published Mar 16, 2007

Unspecified maintenance web pages in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allow remote authenticated users to execute arbitrary commands via shell metachar…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 139 CVEsPage 4 of 6