CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Avaya 1Aura Application Enablement Services Nov 21, 2024 Oct 6, 2022 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A vulnerability related to weak permissions was detected in Avaya Aura Application Enablement Services web application, allowing an administrative user to modify accounts leading to execution of arbitrary code as the roo...Show more |
5Avaya DebianMozilla+2 more27Aura Application Enablement Services Aura Application Server 5300Aura Communication Manager+24 moreNov 21, 2024 Nov 15, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a...Show more |
7Avaya CanonicalDebian+4 more18Aura Application Enablement Services Aura Communication ManagerAura Session Manager+15 moreApr 23, 2026 Nov 16, 2009 N/A· v4 7.1 HIGH· v3 6.6 MEDIUM· v2 The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file. |
2Avaya Busybox5Aura Application Enablement Services Aura Sip Enablement ServicesBusybox+2 moreApr 16, 2026 Apr 4, 2006 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables. |