| OSVDB ID | Disclosure Date | Title |
|
46583
Description:
Unknown / Incomplete
|
2008-06-25
|
Avaya Communication Manager Web Interface Credential Restoration Unspecified Arbitrary Code Execution
|
|
46582
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Web administration interface in Avaya Communication Manager 3.1.x before CM 3.1.4 SP2 and 4.0.x before 4.0.3 SP1 allows remote authenticated administrators to gain root privileges via unknown vectors related to "configuring data viewing or restoring credentials."
|
2008-06-25
|
Avaya Communication Manager Web Interface Data Viewing Configuration Unspecified Arbitrary Code Execution
|
|
46581
Description:
(Description Provided by CVE) : Unspecified vulnerability in the Web administration interface in Avaya Communication Manager 3.1.x before CM 3.1.4 SP2 and 4.0.x before 4.0.3 SP1 allows remote authenticated users to execute arbitrary commands via unknown vectors related to "viewing system logs."
|
2008-06-25
|
Avaya Communication Manager Web Interface System Log Viewing Unspecified Arbitrary Code Execution
|
|
74345
Description:
Unknown / Incomplete
|
2011-04-19
|
Avaya Communication Server 1000 Remote Underflow DoS
|
|
33297
Description:
Avaya Communication Manager in Avaya S8300 Media Server, S8500 Media Server, and S87XX-Series Media Server contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not properly validate JavaScript input passed to the "Login" form field parameter on Communication Manager's login page. This could allow a user to execute arbitrary JavaScript code in the context of the affected application, leading to a loss of integrity.
|
2007-03-07
|
Avaya Communications Manager Login Page XSS
|
|
61010
Description:
(Description Provided by CVE) : Multiple buffer overflows in multiple unspecified implementations of Internet Key Exchange version 1 (IKEv1) have multiple unspecified attack vectors and impacts related to denial of service, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of information in the original sources, it is likely that this candidate will be REJECTed once it is known which implementations are actually vulnerable.
|
2005-11-14
|
Avaya CSU/VSU ISAKMP Protocol Unspecified Malformed Input Remote DoS (PROTOS)
|
|
76657
Description:
Unknown / Incomplete
|
2011-10-18
|
Avaya Identity Engines Ignition Server AdminAccountManager Process GIOP Packet Parsing Access Restriction Bypass
|
|
78922
Description:
Avaya Interaction Center is prone to an overflow condition. The vesporb.dll library within the Avaya IC ORB service fails to properly sanitize user-supplied input resulting in a stack-based buffer overflow. With a specially crafted packet, a remote attacker can potentially cause arbitrary code execution.
|
2012-02-08
|
Avaya Interaction Center vesporb.dll ORB Service Packet Parsing Remote Overflow
|
|
60525
Description:
Unknown / Incomplete
|
2009-09-17
|
Avaya Intuity Audix LX /cgi-bin/smallmenu.pl url Parameter XSS
|
|
60524
Description:
Unknown / Incomplete
|
2009-09-17
|
Avaya Intuity Audix LX /cswebadm/diag/cgi-bin/nslookup.pl Multiple Parameter Arbitrary Command Execution
|
|
60523
Description:
Unknown / Incomplete
|
2009-09-17
|
Avaya Intuity Audix LX /cswebadm/diag/cgi-bin/sendrec.pl Multiple Parameter Arbitrary Command Execution
|
|
60526
Description:
Unknown / Incomplete
|
2009-09-17
|
Avaya Intuity Audix LX Multiple Admin Script JavaScript submit() Method CSRF
|
|
83399
Description:
Avaya IP Office Customer Call Reporter contains a flaw that allows a remote user to execute arbitrary PHP code. This flaw exists because the ImageUpload.ashx script does not properly verify or sanitize user-uploaded files. By uploading a .php file, the remote system will place the file in a user-accessible path. Making a direct request to the uploaded file will allow the user to execute the script.
|
2012-06-28
|
Avaya IP Office Customer Call Reporter ImageUpload.ashx File Upload Remote Code Execution
|
|
71282
Description:
Avaya IP Office Manager contains a flaw that may allow a remote denial of service. The issue is triggered when an error occurs when processing TFTP requests, allowing an attacker to use a crafted packet to cause a denial of service.
|
2011-03-24
|
Avaya IP Office Manager TFTP Request Handling DoS
|
|
73121
Description:
Avaya IP Office Manager contains a flaw that allows a local attacker to traverse outside of a restricted path. The issue is due to the program not properly sanitizing TFTP requests, specifically directory traversal style attacks (e.g., ../../). This directory traversal attack would allow the attacker to access arbitrary files.
|
2011-06-13
|
Avaya IP Office Manager TFTP Request Handling Traversal Arbitrary File Access
|
|
14206
Description:
IP office phone manager contains a flaw that may lead to an unauthorized password exposure. It is possible for any local user to gain access to encrypted passwords that are stored in the registry, which may lead to a loss of confidentiality.
|
2005-02-22
|
Avaya IP Office Phone Manager Registry Cleartext Auth Credential Storage
|
|
38258
Description:
(Description Provided by CVE) : Multiple buffer overflows in unspecified ActiveX controls in COM objects in Avaya IP Softphone R5.2 before SP3, and R6.0, allow remote attackers to execute arbitrary code via unspecified vectors.
|
2007-09-11
|
Avaya IP Softphone ActiveX COM Objects Multiple Unspecified Overflows
|
|
48938
Description:
(Description Provided by CVE) : Unspecified vulnerability in Avaya IP Softphone 6.0 SP4 and 6.01.85 allows remote attackers to cause a denial of service (crash) via a large amount of H.323 data.
|
2008-10-08
|
Avaya IP Softphone H.323 Data Handling Remote DoS
|
|
46588
Description:
(Description Provided by CVE) : Multiple unspecified "input validation" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Storage Server (MSS) 3.x and 4.0, and possibly Communication Manager 3.1.x, allow remote authenticated administrators to execute arbitrary commands as user vexvm via vectors related to (1) SFTP Remote Store configuration; (2) remote FTP storage settings; (3) name server lookup; (4) pinging another host; (5) TCP/IP Networking parameter configuration; (6) the external hosts configuration main page; (7) adding and changing external hosts; (8) Windows domain parameter configuration; (9) date, time, and NTP server configuration; (10) alarm settings; (11) the command line history form; (12) the maintenance form; and (13) the server events form.
|
2008-06-25
|
Avaya Message Storage Server (MSS) Admin Interface Alarm Settings Arbitrary Command Execution
|
|
46587
Description:
Unknown / Incomplete
|
2008-06-25
|
Avaya Message Storage Server (MSS) Admin Interface Command Line History Form Arbitrary Command Execution
|
|
46591
Description:
(Description Provided by CVE) : Multiple unspecified "input validation" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Storage Server (MSS) 3.x and 4.0, and possibly Communication Manager 3.1.x, allow remote authenticated administrators to execute arbitrary commands as user vexvm via vectors related to (1) SFTP Remote Store configuration; (2) remote FTP storage settings; (3) name server lookup; (4) pinging another host; (5) TCP/IP Networking parameter configuration; (6) the external hosts configuration main page; (7) adding and changing external hosts; (8) Windows domain parameter configuration; (9) date, time, and NTP server configuration; (10) alarm settings; (11) the command line history form; (12) the maintenance form; and (13) the server events form.
|
2008-06-25
|
Avaya Message Storage Server (MSS) Admin Interface External Host Modification Arbitrary Command Execution
|
|
46586
Description:
(Description Provided by CVE) : Multiple unspecified "input validation" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Storage Server (MSS) 3.x and 4.0, and possibly Communication Manager 3.1.x, allow remote authenticated administrators to execute arbitrary commands as user vexvm via vectors related to (1) SFTP Remote Store configuration; (2) remote FTP storage settings; (3) name server lookup; (4) pinging another host; (5) TCP/IP Networking parameter configuration; (6) the external hosts configuration main page; (7) adding and changing external hosts; (8) Windows domain parameter configuration; (9) date, time, and NTP server configuration; (10) alarm settings; (11) the command line history form; (12) the maintenance form; and (13) the server events form.
|
2008-06-25
|
Avaya Message Storage Server (MSS) Admin Interface Maintenance Form Arbitrary Command Execution
|
|
46594
Description:
(Description Provided by CVE) : Multiple unspecified "input validation" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Storage Server (MSS) 3.x and 4.0, and possibly Communication Manager 3.1.x, allow remote authenticated administrators to execute arbitrary commands as user vexvm via vectors related to (1) SFTP Remote Store configuration; (2) remote FTP storage settings; (3) name server lookup; (4) pinging another host; (5) TCP/IP Networking parameter configuration; (6) the external hosts configuration main page; (7) adding and changing external hosts; (8) Windows domain parameter configuration; (9) date, time, and NTP server configuration; (10) alarm settings; (11) the command line history form; (12) the maintenance form; and (13) the server events form.
|
2008-06-25
|
Avaya Message Storage Server (MSS) Admin Interface Name Server Lookup Arbitrary Command Execution
|
|
46593
Description:
(Description Provided by CVE) : Multiple unspecified "input validation" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Storage Server (MSS) 3.x and 4.0, and possibly Communication Manager 3.1.x, allow remote authenticated administrators to execute arbitrary commands as user vexvm via vectors related to (1) SFTP Remote Store configuration; (2) remote FTP storage settings; (3) name server lookup; (4) pinging another host; (5) TCP/IP Networking parameter configuration; (6) the external hosts configuration main page; (7) adding and changing external hosts; (8) Windows domain parameter configuration; (9) date, time, and NTP server configuration; (10) alarm settings; (11) the command line history form; (12) the maintenance form; and (13) the server events form.
|
2008-06-25
|
Avaya Message Storage Server (MSS) Admin Interface Ping Utility Arbitrary Command Execution
|
|
46595
Description:
(Description Provided by CVE) : Multiple unspecified "input validation" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Storage Server (MSS) 3.x and 4.0, and possibly Communication Manager 3.1.x, allow remote authenticated administrators to execute arbitrary commands as user vexvm via vectors related to (1) SFTP Remote Store configuration; (2) remote FTP storage settings; (3) name server lookup; (4) pinging another host; (5) TCP/IP Networking parameter configuration; (6) the external hosts configuration main page; (7) adding and changing external hosts; (8) Windows domain parameter configuration; (9) date, time, and NTP server configuration; (10) alarm settings; (11) the command line history form; (12) the maintenance form; and (13) the server events form.
|
2008-06-25
|
Avaya Message Storage Server (MSS) Admin Interface S/FTP Storage Configuration Arbitrary Command Execution
|
|
46585
Description:
(Description Provided by CVE) : Multiple unspecified "input validation" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Storage Server (MSS) 3.x and 4.0, and possibly Communication Manager 3.1.x, allow remote authenticated administrators to execute arbitrary commands as user vexvm via vectors related to (1) SFTP Remote Store configuration; (2) remote FTP storage settings; (3) name server lookup; (4) pinging another host; (5) TCP/IP Networking parameter configuration; (6) the external hosts configuration main page; (7) adding and changing external hosts; (8) Windows domain parameter configuration; (9) date, time, and NTP server configuration; (10) alarm settings; (11) the command line history form; (12) the maintenance form; and (13) the server events form.
|
2008-06-25
|
Avaya Message Storage Server (MSS) Admin Interface Server Event Configuration Arbitrary Command Execution
|
|
46592
Description:
(Description Provided by CVE) : Multiple unspecified "input validation" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Storage Server (MSS) 3.x and 4.0, and possibly Communication Manager 3.1.x, allow remote authenticated administrators to execute arbitrary commands as user vexvm via vectors related to (1) SFTP Remote Store configuration; (2) remote FTP storage settings; (3) name server lookup; (4) pinging another host; (5) TCP/IP Networking parameter configuration; (6) the external hosts configuration main page; (7) adding and changing external hosts; (8) Windows domain parameter configuration; (9) date, time, and NTP server configuration; (10) alarm settings; (11) the command line history form; (12) the maintenance form; and (13) the server events form.
|
2008-06-25
|
Avaya Message Storage Server (MSS) Admin Interface TCP/IP Network Configuration Arbitrary Command Execution
|
|
46589
Description:
(Description Provided by CVE) : Multiple unspecified "input validation" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Storage Server (MSS) 3.x and 4.0, and possibly Communication Manager 3.1.x, allow remote authenticated administrators to execute arbitrary commands as user vexvm via vectors related to (1) SFTP Remote Store configuration; (2) remote FTP storage settings; (3) name server lookup; (4) pinging another host; (5) TCP/IP Networking parameter configuration; (6) the external hosts configuration main page; (7) adding and changing external hosts; (8) Windows domain parameter configuration; (9) date, time, and NTP server configuration; (10) alarm settings; (11) the command line history form; (12) the maintenance form; and (13) the server events form.
|
2008-06-25
|
Avaya Message Storage Server (MSS) Admin Interface Time Settings Arbitrary Command Execution
|
|
46590
Description:
(Description Provided by CVE) : Multiple unspecified "input validation" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Storage Server (MSS) 3.x and 4.0, and possibly Communication Manager 3.1.x, allow remote authenticated administrators to execute arbitrary commands as user vexvm via vectors related to (1) SFTP Remote Store configuration; (2) remote FTP storage settings; (3) name server lookup; (4) pinging another host; (5) TCP/IP Networking parameter configuration; (6) the external hosts configuration main page; (7) adding and changing external hosts; (8) Windows domain parameter configuration; (9) date, time, and NTP server configuration; (10) alarm settings; (11) the command line history form; (12) the maintenance form; and (13) the server events form.
|
2008-06-25
|
Avaya Message Storage Server (MSS) Admin Interface Windows Domain Parameter Arbitrary Command Execution
|
|
22013
Description:
(Description Provided by CVE) : POP3 service in Avaya Modular Messaging Message Storage Server (MSS) 2.0 SP 4 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted packets.
|
2005-12-19
|
Avaya Message Storage Server POP3 Crafted Packet Remote DoS
|