CVE-2014-2171
published 2014-05-02CVE-2014-2171: Heap-based buffer overflow in Cisco TelePresence TC Software 4.x through 6.x before 6.0.1 and TE Software 4.x and 6.0.x before 6.0.2 allows remote attackers to…
PriorityP352critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.59%
88.1th percentile
Heap-based buffer overflow in Cisco TelePresence TC Software 4.x through 6.x before 6.0.1 and TE Software 4.x and 6.0.x before 6.0.2 allows remote attackers to execute arbitrary code via crafted SIP packets, aka Bug ID CSCud81796.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_tc_and_te | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_te_software | — | — |
| cisco | telepresence_te_software | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4hc9-2vw2-236j: Heap-based buffer overflow in Cisco TelePresence TC Software 4
ghsa_unreviewed·2022-05-17
CVE-2014-2171 [HIGH] CWE-119 GHSA-4hc9-2vw2-236j: Heap-based buffer overflow in Cisco TelePresence TC Software 4
Heap-based buffer overflow in Cisco TelePresence TC Software 4.x through 6.x before 6.0.1 and TE Software 4.x and 6.0.x before 6.0.2 allows remote attackers to execute arbitrary code via crafted SIP packets, aka Bug ID CSCud81796.
Red Hat
chromium-browser: Use-after-free in blink
vendor_redhat·2014-11-18·CVSS 7.5
CVE-2014-7907 [HIGH] CWE-416 chromium-browser: Use-after-free in blink
chromium-browser: Use-after-free in blink
Multiple use-after-free vulnerabilities in modules/screen_orientation/ScreenOrientationController.cpp in Blink, as used in Google Chrome before 39.0.2171.65, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger improper handling of a detached frame, related to the (1) lock and (2) unlock methods.
Statement: This issue affects the versions of webkitgtk and webkitgtk3 as shipped with Red Hat Enterprise Linux 6 and 7 respectively.
Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/securit
Red Hat
chromium-browser: Uninitialized memory read in Skia
vendor_redhat·2014-11-18·CVSS 5.0
CVE-2014-7909 [MEDIUM] chromium-browser: Uninitialized memory read in Skia
chromium-browser: Uninitialized memory read in Skia
effects/SkDashPathEffect.cpp in Skia, as used in Google Chrome before 39.0.2171.65, computes a hash key using uninitialized integer values, which might allow remote attackers to cause a denial of service by rendering crafted data.
Statement: This issue did not affect the versions of librsvg2 as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Package: librsvg2 (Red Hat Enterprise Linux 5) - Not affected
Package: librsvg2 (Red Hat Enterprise Linux 6) - Not affected
Package: librsvg2 (Red Hat Enterprise Linux 7) - Not affected
Red Hat
chromium-browser: Unspecified security issues
vendor_redhat·2014-11-18·CVSS 7.5
CVE-2014-7910 [HIGH] chromium-browser: Unspecified security issues
chromium-browser: Unspecified security issues
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Statement: This issue affects the versions of webkitgtk and webkitgtk3 as shipped with Red Hat Enterprise Linux 6 and 7 respectively.
Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
Package: webkitgtk3 (Red Hat Enterprise Linux 7) - Will not fix
Red Hat
chromium-browser: Use-after-free in pepper plugins
vendor_redhat·2014-11-18·CVSS 7.5
CVE-2014-7906 [HIGH] CWE-416 chromium-browser: Use-after-free in pepper plugins
chromium-browser: Use-after-free in pepper plugins
Use-after-free vulnerability in the Pepper plugins in Google Chrome before 39.0.2171.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted Flash content that triggers an attempted PepperMediaDeviceManager access outside of the object's lifetime.
Red Hat
chromium-browser: Buffer overflow in Skia
vendor_redhat·2014-11-18·CVSS 7.5
CVE-2014-7904 [HIGH] chromium-browser: Buffer overflow in Skia
chromium-browser: Buffer overflow in Skia
Buffer overflow in Skia, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Statement: This issue did not affect the versions of librsvg2 as shipped with Red Hat Enterprise Linux 5 and 6. This issue affects the version of librsvg2 as shipped with Red Hat Enterprise Linux 7.
Package: librsvg2 (Red Hat Enterprise Linux 5) - Not affected
Package: librsvg2 (Red Hat Enterprise Linux 6) - Not affected
Package: librsvg2 (Red Hat Enterprise Linux 7) - Will not fix
Red Hat
chromium-browser: Flaw allowing navigation to intents that do not have the BROWSABLE category
vendor_redhat·2014-11-18·CVSS 5.0
CVE-2014-7905 [MEDIUM] chromium-browser: Flaw allowing navigation to intents that do not have the BROWSABLE category
chromium-browser: Flaw allowing navigation to intents that do not have the BROWSABLE category
Google Chrome before 39.0.2171.65 on Android does not prevent navigation to a URL in cases where an intent for the URL lacks CATEGORY_BROWSABLE, which allows remote attackers to bypass intended access restrictions via a crafted web site.
Statement: Not vulnerable. This issue does not affect the version of chromium-browser as shipped with Red Hat Enterprise Linux 6.
Package: chromium-browser (Red Hat Enterprise Linux 6) - Not affected
Red Hat
chromium-browser: Integer overflow in media
vendor_redhat·2014-11-18·CVSS 7.5
CVE-2014-7908 [HIGH] CWE-190 chromium-browser: Integer overflow in media
chromium-browser: Integer overflow in media
Multiple integer overflows in the CheckMov function in media/base/container_names.cc in Google Chrome before 39.0.2171.65 allow remote attackers to cause a denial of service or possibly have unspecified other impact via a large atom in (1) MPEG-4 or (2) QuickTime .mov data.
Statement: This issue affects the versions of webkitgtk and webkitgtk3 as shipped with Red Hat Enterprise Linux 6 and 7 respectively.
Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not
Cisco
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
vendor_cisco·2014-04-30·CVSS 7.5
CVE-2014-2162 [HIGH] CWE-119 Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Cisco TelePresence TC and TE Software are affected by the following vulnerabilities:
Six Session Initiation Protocol (SIP) denial of service vulnerabilities
Cisco TelePresence TC and TE Software DNS Buffer Overflow Vulnerability
Cisco TelePresence TC and TE Software Input Validation Vulnerability
Cisco TelePresence TC and TE Software tshell Command Injection Vulnerability
Cisco TelePresence TC and TE Software Heap Overflow Vulnerability
Cisco TelePresence TC and TE Software U-Boot Buffer Overflow Vulnerability
Cisco TelePresence TC and TE Software Unauthenticated Serial Port Access Vulnerability
Cisco TelePresence TC H.225 Denial of Service Vulnerability
Successful exploitation of these vulnerabilities could allow an atta
Cisco
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
vendor_cisco
CVE-2014-2171 Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
CVE-2014-2171: Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Cisco TelePresence TC and TE Software are affected by the following vulnerabilities: Six Session Initiation Protocol (SIP) denial of service vulnerabilities Cisco TelePresence TC and TE Software DNS Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Input Validation Vulnerability Cisco TelePresence TC and TE Software tshell Command Injection Vulnerability Cisco TelePresence TC and TE Software Heap Overflow Vulnerability Cisco TelePresence TC and TE Software U-Boot Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Unauthenticated Serial Port Access Vulnerability Cisco TelePresence TC H.225 Denial of Service Vulnerability Successful exploitation of these vulnerabilities could a
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-05-02
Published