CVE-2012-5416
published 2012-11-02CVE-2012-5416: Buffer overflow in Cisco Unified MeetingPlace Web Conferencing before 7.1MR1 Patch 1, 8.0 before 8.0MR1 Patch 1, and 8.5 before 8.5MR3 allows remote attackers…
PriorityP337high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.02%
78.7th percentile
Buffer overflow in Cisco Unified MeetingPlace Web Conferencing before 7.1MR1 Patch 1, 8.0 before 8.0MR1 Patch 1, and 8.5 before 8.5MR3 allows remote attackers to cause a denial of service (daemon hang) via unspecified parameters in a POST request, aka Bug ID CSCua66341.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_meetingplace | <= 7.1 | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace_web_conferencing | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco8.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-phh9-5f9f-v6mm: Buffer overflow in Cisco Unified MeetingPlace Web Conferencing before 7
ghsa_unreviewed·2022-05-17
CVE-2012-5416 [HIGH] CWE-119 GHSA-phh9-5f9f-v6mm: Buffer overflow in Cisco Unified MeetingPlace Web Conferencing before 7
Buffer overflow in Cisco Unified MeetingPlace Web Conferencing before 7.1MR1 Patch 1, 8.0 before 8.0MR1 Patch 1, and 8.5 before 8.5MR3 allows remote attackers to cause a denial of service (daemon hang) via unspecified parameters in a POST request, aka Bug ID CSCua66341.
Cisco
Multiple Vulnerabilities in Cisco Unified MeetingPlace Web Conferencing
vendor_cisco·2012-10-31·CVSS 8.5
CVE-2012-0337 [HIGH] CWE-119 Multiple Vulnerabilities in Cisco Unified MeetingPlace Web Conferencing
Multiple Vulnerabilities in Cisco Unified MeetingPlace Web Conferencing
Cisco Unified MeetingPlace Web Conferencing is affected by two vulnerabilities:
Cisco Unified MeetingPlace Web Conferencing SQL Injection Vulnerability
Cisco Unified MeetingPlace Web Conferencing Buffer Overrun Vulnerability
Exploitation of the Cisco Unified MeetingPlace Web Conferencing SQL Injection Vulnerability may allow an unauthenticated, remote attacker to send Structured Query Language (SQL) commands to manipulate the MeetingPlace database stores information about server
configuration, meetings, and users. These commands may be used to create,
delete, or alter some of the information in the Cisco Unified
MeetingPlace Web Conferencing database.
Exploitation of the Cisco Unified MeetingPlace Web Conferencing
Cisco
Multiple Vulnerabilities in Cisco Unified MeetingPlace Web Conferencing
vendor_cisco
CVE-2012-5416 Multiple Vulnerabilities in Cisco Unified MeetingPlace Web Conferencing
CVE-2012-5416: Multiple Vulnerabilities in Cisco Unified MeetingPlace Web Conferencing
Cisco Unified MeetingPlace Web Conferencing is affected by two vulnerabilities: Cisco Unified MeetingPlace Web Conferencing SQL Injection Vulnerability Cisco Unified MeetingPlace Web Conferencing Buffer Overrun Vulnerability Exploitation of the Cisco Unified MeetingPlace Web Conferencing SQL Injection Vulnerability may allow an unauthenticated, remote attacker to send Structured Query Language (SQL) commands to manipulate the MeetingPlace database stores information about server configuration, meetings, and users. These commands may be used to create, delete, or alter some of the information in the Cisco Unified MeetingPlace Web Conferencing database. Exploitation of the Cisco Unified MeetingPlace Web Co
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/86859http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20121031-mphttps://exchange.xforce.ibmcloud.com/vulnerabilities/79721http://osvdb.org/86859http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20121031-mphttps://exchange.xforce.ibmcloud.com/vulnerabilities/79721
2012-11-02
Published