CVE-2009-2865
published 2009-09-28CVE-2009-2865: Buffer overflow in the login implementation in the Extension Mobility feature in the Unified Communications Manager Express (CME) component in Cisco IOS…
high7.6CVSS 3.1
AVNACHAuNCCICAC
Buffer overflow in the login implementation in the Extension Mobility feature in the Unified Communications Manager Express (CME) component in Cisco IOS 12.4XW, 12.4XY, 12.4XZ, and 12.4YA allows remote attackers to execute arbitrary code or cause a denial of service via crafted HTTP requests, aka Bug ID CSCsq58779.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | unified_communications_manager_express | — | — |
Cisco
Cisco Unified Communications Manager Express Vulnerability
vendor_cisco·2009-09-23·CVSS 7.6
CVE-2009-2865 [HIGH] CWE-119 Cisco Unified Communications Manager Express Vulnerability
Cisco Unified Communications Manager Express Vulnerability
Cisco IOS® devices that are configured for
Cisco Unified Communications Manager Express (CME) and the Extension Mobility
feature are vulnerable to a buffer overflow vulnerability. Successful
exploitation of this vulnerability may result in the execution of arbitrary
code or a Denial of Service (DoS) condition on an affected device.
Cisco has released software updates that address this vulnerability.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20090923-cme.
Note: The September 23, 2009, Cisco IOS Security Advisory bundled
publication includes eleven Security Advisories. Ten of the advisories address
vulnerabilities in Cisco IOS Software, and one advisory addr
Cisco
Cisco Unified Communications Manager Express Vulnerability
vendor_cisco
CVE-2009-2865 Cisco Unified Communications Manager Express Vulnerability
CVE-2009-2865: Cisco Unified Communications Manager Express Vulnerability
Cisco IOS � devices that are configured for Cisco Unified Communications Manager Express (CME) and the Extension Mobility feature are vulnerable to a buffer overflow vulnerability. Successful exploitation of this vulnerability may result in the execution of arbitrary code or a Denial of Service (DoS) condition on an affected device. Cisco has released software updates that address this vulnerability. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20090923-cme . Note: The September 23, 2009, Cisco IOS Security Advisory bundled publication includes eleven Security Advisories. Ten of the advisories address vulnerabilities in Cisco IOS Software, and one a
GHSA
GHSA-jvhf-p5j4-xwrc: Buffer overflow in the login implementation in the Extension Mobility feature in the Unified Communications Manager Express (CME) component in Cisco I
ghsa_unreviewed·2022-05-02
CVE-2009-2865 [HIGH] CWE-119 GHSA-jvhf-p5j4-xwrc: Buffer overflow in the login implementation in the Extension Mobility feature in the Unified Communications Manager Express (CME) component in Cisco I
Buffer overflow in the login implementation in the Extension Mobility feature in the Unified Communications Manager Express (CME) component in Cisco IOS 12.4XW, 12.4XY, 12.4XZ, and 12.4YA allows remote attackers to execute arbitrary code or cause a denial of service via crafted HTTP requests, aka Bug ID CSCsq58779.
No detection rules found.
No public exploits indexed.
http://osvdb.org/58335http://tools.cisco.com/security/center/viewAlert.x?alertId=18884http://www.cisco.com/en/US/products/products_security_advisory09186a0080af8116.shtmlhttp://www.securityfocus.com/bid/36498http://www.securitytracker.com/id?1022932http://www.vupen.com/english/advisories/2009/2758https://exchange.xforce.ibmcloud.com/vulnerabilities/53448http://osvdb.org/58335http://tools.cisco.com/security/center/viewAlert.x?alertId=18884http://www.cisco.com/en/US/products/products_security_advisory09186a0080af8116.shtmlhttp://www.securityfocus.com/bid/36498http://www.securitytracker.com/id?1022932http://www.vupen.com/english/advisories/2009/2758https://exchange.xforce.ibmcloud.com/vulnerabilities/53448
2009-09-28
Published