cbcvebase.

Cisco Unified Communications Manager vulnerabilities

213 known vulnerabilities affecting cisco/unified_communications_manager.

Total CVEs
213
CISA KEV
2
actively exploited
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL12HIGH76MEDIUM117LOW1UNKNOWN6

Vulnerabilities

Page 11 of 11
CVE-2007-4634CRITICALCVSS 9.3PoCv3.3\(5\)v3.3\(5\)sr1+13 more2007-08-31
CVE-2007-4634 [CRITICAL] CWE-89 CVE-2007-4634: Multiple SQL injection vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM Multiple SQL injection vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to execute arbitrary SQL commands via the lang variable to the (1) user or (2) admin logon page, aka CSCsi64265.
nvd
CVE-2007-4633MEDIUMCVSS 4.3v4.2.3sr2v4.2.3sr2b2007-08-31
CVE-2007-4633 [MEDIUM] CWE-79 CVE-2007-4633: Multiple cross-site scripting (XSS) vulnerabilities in Cisco CallManager and Unified Communications Multiple cross-site scripting (XSS) vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to inject arbitrary web script or HTML via the lang variable to the (1) user or (2) admin logon page, aka CSCsi10728.
nvd
CVE-2007-4294MEDIUMCVSS 6.8v5.0v5.1+1 more2007-08-09
CVE-2007-4294 [MEDIUM] CVE-2007-4294: Unspecified vulnerability in Cisco Unified Communications Manager (CUCM) 5.0, 5.1, and 6.0, and IOS Unspecified vulnerability in Cisco Unified Communications Manager (CUCM) 5.0, 5.1, and 6.0, and IOS 12.0 through 12.4, allows remote attackers to execute arbitrary code via a malformed SIP packet, aka CSCsi80102.
nvd
CVE-2006-5277CRITICALCVSS 9.3≥ 4.3, ≤ 4.3\(1\)≥ 5.1, ≤ 5.1\(1\)2007-07-15
CVE-2006-5277 [CRITICAL] CVE-2006-5277: Off-by-one error in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Uni Off-by-one error in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via a crafted packet that triggers a heap-based buffer overflow.
nvd
CVE-2006-5278CRITICALCVSS 10.0≥ 4.3, ≤ 4.3\(1\)2007-07-15
CVE-2006-5278 [CRITICAL] CVE-2006-5278: Integer overflow in the Real-Time Information Server (RIS) Data Collector service (RisDC.exe) in Cis Integer overflow in the Real-Time Information Server (RIS) Data Collector service (RisDC.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via crafted packets, resulting in a heap-based buffer overflow.
nvd
CVE-2007-3775HIGHCVSS 7.8v5.0v5.1\(1\)+1 more2007-07-15
CVE-2007-3775 [HIGH] CVE-2007-3775: Unspecified vulnerability in Cisco Unified Communications Manager (CUCM, formerly CallManager) and U Unspecified vulnerability in Cisco Unified Communications Manager (CUCM, formerly CallManager) and Unified Presence Server (CUPS) allows remote attackers to cause a denial of service (loss of cluster services) via unspecified vectors, aka (1) CSCsj09859 and (2) CSCsj19985.
nvd
CVE-2007-3776MEDIUMCVSS 5.0v5.0v5.1\(1\)+1 more2007-07-15
CVE-2007-3776 [MEDIUM] CVE-2007-3776: Cisco Unified Communications Manager (CUCM, formerly CallManager) and Unified Presence Server (CUPS) Cisco Unified Communications Manager (CUCM, formerly CallManager) and Unified Presence Server (CUPS) allow remote attackers to obtain sensitive information via unspecified vectors that reveal the SNMP community strings and configuration settings, aka (1) CSCsj20668 and (2) CSCsj25962.
nvd
CVE-2010-0573UNKNOWN
CVE-2010-0573 Cisco Unified Communications Manager Denial of Service Vulnerabilities CVE-2010-0573: Cisco Unified Communications Manager Denial of Service Vulnerabilities Cisco Unified Communications Manager (formerly Cisco CallManager) contains multiple denial of service (DoS) vulnerabilities that if exploited could cause an interruption of voice services. The Session Initiation Protocol (SIP), Skinny Client Control Protocol (SCCP) and Computer Telephony Integration (CTI) Manager services are a
cisco
CVE-2018-0118UNKNOWNCVSS 3.0
CVE-2018-0118 Cisco Unified Communications Manager Cross-Site Scripting Vulnerability CVE-2018-0118: Cisco Unified Communications Manager Cross-Site Scripting Vulnerability A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to perform a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-su
cisco
CVE-2017-12302UNKNOWNCVSS 3.0
CVE-2017-12302 Cisco Unified Communications Manager SQL Injection Vulnerability CVE-2017-12302: Cisco Unified Communications Manager SQL Injection Vulnerability A vulnerability in the Cisco Unified Communications Manager SQL database interface could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries. The vulnerability is due to a lack of input validation on user-supplied input in SQL queries. An attacker could exploit this vulne
cisco
CVE-2018-0198UNKNOWNCVSS 3.0
CVE-2018-0198 Cisco Unified Communications Manager Information Disclosure Vulnerability CVE-2018-0198: Cisco Unified Communications Manager Information Disclosure Vulnerability A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view sensitive data. The vulnerability is due to insufficient protection of database tables. An attacker could exploit this vulnerability by browsing to a specific URL. A successful exploit could
cisco
CVE-2016-1317UNKNOWN
CVE-2016-1317 Cisco Unified Communications Manager Information Disclosure Vulnerability CVE-2016-1317: Cisco Unified Communications Manager Information Disclosure Vulnerability A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view sensitive data. The vulnerability is due to insufficient protection of database tables. An attacker could exploit this vulnerability by browsing to a specific URL. An exploit could allow the a
cisco
CVE-2016-1308UNKNOWN
CVE-2016-1308 Cisco Unified Communications Manager SQL Injection Vulnerability CVE-2016-1308: Cisco Unified Communications Manager SQL Injection Vulnerability A vulnerability in the Cisco Unified Communications Manager SQL database interface could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries. The vulnerability is due to a lack of input validation on user-supplied input in SQL queries. An attacker could exploit this vulnera
cisco