Avaya Aura Communication Manager vulnerabilities
10 known vulnerabilities affecting avaya/aura_communication_manager.
Total CVEs
10
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2022-2249MEDIUMCVSS 6.7≥ 8.0, < 8.1.3.4v10.1.0.02022-10-12
CVE-2022-2249 [HIGH] CWE-269 CVE-2022-2249: Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager tha
Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager that may allow local administrative users to escalate their privileges. This issue affects Communication Manager versions 8.0.0.0 through 8.1.3.3 and 10.1.0.0.
nvd
CVE-2020-7029HIGHCVSS 8.8≥ 7.0, ≤ 7.1.3.4≥ 8.0, < 8.1.0.02020-08-11
CVE-2020-7029 [MEDIUM] CWE-352 CVE-2020-7029: A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager and Avaya Aura Messaging. This vulnerability could allow an unauthenticated remote attacker to perform Web administration actions with the privileged level of the authenticated user. Affected versions of
nvd
CVE-2016-5285HIGHCVSS 7.5≥ 6.0, ≤ 6.3.117.0v7.02019-11-15
CVE-2016-5285 [HIGH] CWE-476 CVE-2016-5285: A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missin
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
nvd
CVE-2018-15617HIGHCVSS 7.5≥ 6.3.0.1, ≤ 6.3.17.0≥ 7.0, < 7.1.3.2+1 more2019-02-01
CVE-2018-15617 [MEDIUM] CWE-399 CVE-2018-15617: A vulnerability in the "capro" (Call Processor) process component of Avaya Aura Communication Manage
A vulnerability in the "capro" (Call Processor) process component of Avaya Aura Communication Manager could allow a remote, unauthenticated user to cause denial of service. Affected versions include 6.3.x, all 7.x versions prior to 7.1.3.2, and all 8.x versions prior to 8.0.1.
nvd
CVE-2018-15611MEDIUMCVSS 6.7≥ 6.3.0.1, ≤ 6.3.17.0≥ 7.0, < 7.1.3.12018-09-27
CVE-2018-15611 [MEDIUM] CWE-284 CVE-2018-15611: A vulnerability in the local system administration component of Avaya Aura Communication Manager can
A vulnerability in the local system administration component of Avaya Aura Communication Manager can allow an authenticated, privileged user on the local system to gain root privileges. Affected versions include 6.3.x and all 7.x version prior to 7.1.3.1.
nvd
CVE-2010-2943HIGHCVSS 8.1PoCv5.22010-09-30
CVE-2010-2943 [HIGH] CWE-200 CVE-2010-2943: The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees be
The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned to an active file but were previously assigned to an unlinked file, by accessing a stale NFS filehandl
nvd
CVE-2010-2942MEDIUMCVSS 5.5v5.22010-09-21
CVE-2010-2942 [MEDIUM] CWE-401 CVE-2010-2942: The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-r
The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information from kernel memory via vectors related to (1) the tcf_gact_dump function in net/sched/act_gac
nvd
CVE-2010-2492HIGHCVSS 7.8v5.22010-09-08
CVE-2010-2492 [HIGH] CWE-120 CVE-2010-2492: Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem
Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or cause a denial of service (system crash) via unspecified vectors.
nvd
CVE-2010-2798HIGHCVSS 7.8v5.22010-09-08
CVE-2010-2798 [HIGH] CWE-476 CVE-2010-2798: The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incor
The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact by renaming a file in a GFS2 filesystem, rela
nvd
CVE-2009-3939HIGHCVSS 7.1v5.22009-11-16
CVE-2009-3939 [HIGH] CWE-732 CVE-2009-3939: The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world
The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.
nvd