CVEs (10)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager that may allow local administrative users to escalate their privileges. This issue affects Communication Manager versions 8...Show more |
1Avaya 2Aura Communication Manager Aura MessagingJun 17, 2026 Aug 11, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager and Avaya Aura Messaging. This vulnerability could allow an unauthenti...Show more |
5Avaya DebianMozilla+2 more27Aura Application Enablement Services Aura Application Server 5300Aura Communication Manager+24 moreNov 21, 2024 Nov 15, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a...Show more |
1Avaya 1Aura Communication Manager Nov 21, 2024 Feb 1, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the "capro" (Call Processor) process component of Avaya Aura Communication Manager could allow a remote, unauthenticated user to cause denial of service. Affected versions include 6.3.x, all 7.x versio...Show more |
1Avaya 1Aura Communication Manager Nov 21, 2024 Sep 27, 2018 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability in the local system administration component of Avaya Aura Communication Manager can allow an authenticated, privileged user on the local system to gain root privileges. Affected versions include 6.3.x an...Show more |
4Avaya CanonicalLinux+1 more10Aura Communication Manager Aura Presence ServicesAura Session Manager+7 moreApr 29, 2026 Sep 30, 2010 N/A· v4 8.1 HIGH· v3 6.4 MEDIUM· v2 The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk bl...Show more |
6Avaya CanonicalLinux+3 more13Aura Communication Manager Aura Presence ServicesAura Session Manager+10 moreApr 29, 2026 Sep 21, 2010 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to o...Show more |
7Avaya CanonicalDebian+4 more15Aura Communication Manager Aura Presence ServicesAura Session Manager+12 moreApr 29, 2026 Sep 8, 2010 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial o...Show more |
3Avaya LinuxVmware9Aura Communication Manager Aura Presence ServicesAura Session Manager+6 moreApr 29, 2026 Sep 8, 2010 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or cause a denial of service (system crash)...Show more |
7Avaya CanonicalDebian+4 more18Aura Application Enablement Services Aura Communication ManagerAura Session Manager+15 moreApr 23, 2026 Nov 16, 2009 N/A· v4 7.1 HIGH· v3 6.6 MEDIUM· v2 The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file. |