Severity
10.0CRITICAL
EPSS
7.4%
top 8.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 2
Latest updateMay 17

Description

Heap-based buffer overflow in Cisco TelePresence TC Software 4.x through 6.x before 6.0.1 and TE Software 4.x and 6.0.x before 6.0.2 allows remote attackers to execute arbitrary code via crafted SIP packets, aka Bug ID CSCud81796.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-4hc9-2vw2-236j: Heap-based buffer overflow in Cisco TelePresence TC Software 42022-05-17
CVEList
CVE-2014-2171: Heap-based buffer overflow in Cisco TelePresence TC Software 42014-05-02

📋Vendor Advisories

8
Red Hat
chromium-browser: Use-after-free in blink2014-11-18
Red Hat
chromium-browser: Uninitialized memory read in Skia2014-11-18
Red Hat
chromium-browser: Unspecified security issues2014-11-18
Red Hat
chromium-browser: Use-after-free in pepper plugins2014-11-18
Red Hat
chromium-browser: Buffer overflow in Skia2014-11-18