← Back

Avaya

avaya

139 CVEs • 158 products

Products (158)

Click to collapse
Toggle
S8300
s8300
S8500
s8500
S8700
s8700
S8100
s8100
Ip Office
ip_office
Intuity Audix
intuity_audix
S3400
s3400
Iq
iq
Argent Office
argent_office
Mn100
mn100
Cvlan
cvlan
Libsafe
libsafe
Sg200
sg200
Sg203
sg203
Sg208
sg208
Sg5
sg5
Vsu
vsu
Ip Soft Phone
ip_soft_phone
S8710
s8710
One X
one-x
Voice Portal
voice_portal
Media Server
media_server
Spaces
spaces
Intuity Lx
intuity_lx
Cajun M770 Atm
cajun_m770-atm
Cajun P130
cajun_p130
Cajun P330
cajun_p330
Cajun P550
cajun_p550
Cajun P550r
cajun_p550r
Cajun P580
cajun_p580
Cajun P880
cajun_p880
Cajun P882
cajun_p882
Wireless Ap 3
wireless_ap-3
Wireless Ap 4
wireless_ap-4
Wireless Ap 5
wireless_ap-5
Wireless Ap 6
wireless_ap-6
Wireless Ap 7
wireless_ap-7
Wireless Ap 8
wireless_ap-8
Vpnremote
vpnremote
Vsu 100
vsu_100
Vsu 10000
vsu_10000
Vsu 2000
vsu_2000
Vsu 7500
vsu_7500
Csu 5000
csu_5000
Voip Handset
voip_handset
Agent Access
agent_access
Callpilot
callpilot
Ip Agent
ip_agent

CVEs (139)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Avaya
Microsoft
35Agent Access
Aura Conferencing Standard EditionBasic Call Management System Reporting Desktop+32 more
Apr 29, 2026
Apr 13, 2011
N/A· v4
N/A· v3
7.2 HIGH· v2
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users...Show more
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different vulnerability than other "Vulnerability Type 2" CVEs listed in MS11-034, aka "Win32k Null Pointer De-reference Vulnerability."Show less
4Avaya
CanonicalLinux+1 more
10Aura Communication Manager
Aura Presence ServicesAura Session Manager+7 more
Apr 29, 2026
Sep 30, 2010
N/A· v4
8.1 HIGH· v3
6.4 MEDIUM· v2
The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk bl...Show more
The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned to an active file but were previously assigned to an unlinked file, by accessing a stale NFS filehandle.Show less
6Avaya
CanonicalLinux+3 more
13Aura Communication Manager
Aura Presence ServicesAura Session Manager+10 more
Apr 29, 2026
Sep 21, 2010
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to o...Show more
The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information from kernel memory via vectors related to (1) the tcf_gact_dump function in net/sched/act_gact.c, (2) the tcf_mirred_dump function in net/sched/act_mirred.c, (3) the tcf_nat_dump function in net/sched/act_nat.c, (4) the tcf_simp_dump function in net/sched/act_simple.c, and (5) the tcf_skbedit_dump function in net/sched/act_skbedit.c.Show less
7Avaya
CanonicalDebian+4 more
15Aura Communication Manager
Aura Presence ServicesAura Session Manager+12 more
Apr 29, 2026
Sep 8, 2010
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial o...Show more
The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact by renaming a file in a GFS2 filesystem, related to the gfs2_rename function in fs/gfs2/ops_inode.c.Show less
3Avaya
LinuxVmware
9Aura Communication Manager
Aura Presence ServicesAura Session Manager+6 more
Apr 29, 2026
Sep 8, 2010
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or cause a denial of service (system crash)...Show more
Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or cause a denial of service (system crash) via unspecified vectors.Show less
7Avaya
CanonicalDebian+4 more
18Aura Application Enablement Services
Aura Communication ManagerAura Session Manager+15 more
Apr 23, 2026
Nov 16, 2009
N/A· v4
7.1 HIGH· v3
6.6 MEDIUM· v2
The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.
1Avaya
1Communication Manager
Apr 23, 2026
Apr 10, 2009
N/A· v4
N/A· v3
9.0 HIGH· v2
Unspecified vulnerability in the Web administration interface in Avaya Communication Manager 3.1.x before CM 3.1.4 SP2 and 4.0.x before 4.0.3 SP1 allows remote authenticated users to execute arbitrary commands via unknow...Show more
Unspecified vulnerability in the Web administration interface in Avaya Communication Manager 3.1.x before CM 3.1.4 SP2 and 4.0.x before 4.0.3 SP1 allows remote authenticated users to execute arbitrary commands via unknown vectors related to "viewing system logs."Show less
1Avaya
1Communication Manager
Apr 23, 2026
Apr 10, 2009
N/A· v4
N/A· v3
9.0 HIGH· v2
Unspecified vulnerability in the Web administration interface in Avaya Communication Manager 3.1.x before CM 3.1.4 SP2 and 4.0.x before 4.0.3 SP1 allows remote authenticated administrators to gain root privileges via unk...Show more
Unspecified vulnerability in the Web administration interface in Avaya Communication Manager 3.1.x before CM 3.1.4 SP2 and 4.0.x before 4.0.3 SP1 allows remote authenticated administrators to gain root privileges via unknown vectors related to "configuring data viewing or restoring credentials."Show less
1Avaya
2Communication Manager
Sip Enablement Services
Apr 23, 2026
Apr 10, 2009
N/A· v4
N/A· v3
9.0 HIGH· v2
Unspecified vulnerability in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, allows remote authenticated users to execute arbitrary command...Show more
Unspecified vulnerability in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, allows remote authenticated users to execute arbitrary commands via unknown vectors related to configuration of "local data viewing or restoring parameters."Show less
1Avaya
2Communication Manager
Sip Enablement Services
Apr 23, 2026
Apr 10, 2009
N/A· v4
N/A· v3
9.0 HIGH· v2
Unspecified vulnerability in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x and 4.x, allows remote authenticated administrators to gain roo...Show more
Unspecified vulnerability in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x and 4.x, allows remote authenticated administrators to gain root privileges via unknown vectors related to configuration of "data viewing or restoring parameters."Show less
1Avaya
2Communication Manager
Sip Enablement Services
Apr 23, 2026
Apr 10, 2009
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, does not perform authentication for certain functionality, which allows remote attackers to...Show more
The Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, does not perform authentication for certain functionality, which allows remote attackers to obtain sensitive information and access restricted functionality via (1) the certificate installation utility, (2) unspecified scripts in the objects folder, (3) an "unnecessary default application," (4) unspecified scripts in the states folder, (5) an unspecified "default application" that lists server configuration, and (6) "full system help."Show less
1Avaya
2Communication Manager
Sip Enablement Services
Apr 23, 2026
Apr 10, 2009
N/A· v4
N/A· v3
7.8 HIGH· v2
Multiple unspecified vulnerabilities in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, allow remote attackers to obtain (1) application se...Show more
Multiple unspecified vulnerabilities in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, allow remote attackers to obtain (1) application server configuration, (2) database server configuration including encrypted passwords, (3) a system utility that decrypts "subscriber table passwords," (4) a system utility that decrypts database passwords, and (5) a system utility that encrypts "subscriber table passwords."Show less
1Avaya
1Communication Manager
Apr 23, 2026
Apr 1, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unspecified vulnerability in the SIP server in SIP Enablement Services (SES) in Avaya Communication Manager 3.1.x and 4.x allows remote authenticated users to cause a denial of service (resource consumption) via unknown...Show more
Unspecified vulnerability in the SIP server in SIP Enablement Services (SES) in Avaya Communication Manager 3.1.x and 4.x allows remote authenticated users to cause a denial of service (resource consumption) via unknown vectors.Show less
1Avaya
1Communication Manager
Apr 23, 2026
Apr 1, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in SIP Enablement Services (SES) in Avaya Communication Manager 3.1.x and 4.x allows remote attackers to gain privileges and cause a denial of service via unknown vectors related to reuse of val...Show more
Unspecified vulnerability in SIP Enablement Services (SES) in Avaya Communication Manager 3.1.x and 4.x allows remote attackers to gain privileges and cause a denial of service via unknown vectors related to reuse of valid credentials.Show less
1Avaya
1Communication Manager
Apr 23, 2026
Apr 1, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple SQL injection vulnerabilities in Avaya SIP Enablement Services (SES) in Avaya Avaya Communication Manager 3.x, 4.0, and 5.0 (1) allow remote attackers to execute arbitrary SQL commands via unspecified vectors re...Show more
Multiple SQL injection vulnerabilities in Avaya SIP Enablement Services (SES) in Avaya Avaya Communication Manager 3.x, 4.0, and 5.0 (1) allow remote attackers to execute arbitrary SQL commands via unspecified vectors related to profiles in the SIP Personal Information Manager (SPIM) in the web interface; and allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to (2) permissions for SPIM profiles in the web interface and (3) a crafted SIP request to the SIP server.Show less
8Avaya
Christophe.varoquiDebian+5 more
11Ctpview
Debian LinuxFedora+8 more
Apr 23, 2026
Mar 30, 2009
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writab...Show more
The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath daemon.Show less
1Avaya
1Ip Soft Phone
Apr 23, 2026
Feb 14, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in Avaya IP Softphone 6.0 SP4 and 6.01.85 allows remote attackers to cause a denial of service (crash) via a large amount of H.323 data.
1Avaya
1One X
Apr 23, 2026
Feb 14, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Avaya one-X Desktop Edition 2.1.0.78 allows remote attackers to cause a denial of service (crash) via unspecified vectors.
2Avaya
Citrix
2Broadcast Server
Broadcast Server
Apr 23, 2026
Jan 9, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in login.asp in Citrix Application Gateway - Broadcast Server (BCS) before 6.1, as used by Avaya AG250 - Broadcast Server before 2.0 and possibly other products, allows remote attackers to exe...Show more
SQL injection vulnerability in login.asp in Citrix Application Gateway - Broadcast Server (BCS) before 6.1, as used by Avaya AG250 - Broadcast Server before 2.0 and possibly other products, allows remote attackers to execute arbitrary SQL commands via the txtUID parameter.Show less
1Avaya
1Communication Manager
Apr 23, 2026
Dec 24, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple unspecified vulnerabilities in the web management interface in Avaya Communication Manager (CM) 3.1.x, 4.0.3, and 5.x allow remote attackers to read (1) configuration files, (2) log files, (3) binary image files...Show more
Multiple unspecified vulnerabilities in the web management interface in Avaya Communication Manager (CM) 3.1.x, 4.0.3, and 5.x allow remote attackers to read (1) configuration files, (2) log files, (3) binary image files, and (4) help files via unknown vectors.Show less