← Back

Avaya

avaya

139 CVEs • 158 products

Products (158)

Click to collapse
Toggle
S8300
s8300
S8500
s8500
S8700
s8700
S8100
s8100
Ip Office
ip_office
Intuity Audix
intuity_audix
S3400
s3400
Iq
iq
Argent Office
argent_office
Mn100
mn100
Cvlan
cvlan
Libsafe
libsafe
Sg200
sg200
Sg203
sg203
Sg208
sg208
Sg5
sg5
Vsu
vsu
Ip Soft Phone
ip_soft_phone
S8710
s8710
One X
one-x
Voice Portal
voice_portal
Media Server
media_server
Spaces
spaces
Intuity Lx
intuity_lx
Cajun M770 Atm
cajun_m770-atm
Cajun P130
cajun_p130
Cajun P330
cajun_p330
Cajun P550
cajun_p550
Cajun P550r
cajun_p550r
Cajun P580
cajun_p580
Cajun P880
cajun_p880
Cajun P882
cajun_p882
Wireless Ap 3
wireless_ap-3
Wireless Ap 4
wireless_ap-4
Wireless Ap 5
wireless_ap-5
Wireless Ap 6
wireless_ap-6
Wireless Ap 7
wireless_ap-7
Wireless Ap 8
wireless_ap-8
Vpnremote
vpnremote
Vsu 100
vsu_100
Vsu 10000
vsu_10000
Vsu 2000
vsu_2000
Vsu 7500
vsu_7500
Csu 5000
csu_5000
Voip Handset
voip_handset
Agent Access
agent_access
Callpilot
callpilot
Ip Agent
ip_agent

CVEs (139)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Avaya
1Communication Manager
Apr 23, 2026
Dec 24, 2008
N/A· v4
N/A· v3
9.0 HIGH· v2
Multiple unspecified vulnerabilities in the web management interface in Avaya Communication Manager (CM) 3.1 before 3.1.4 SP2, 4.0 before 4.0.3 SP1, and 5.0 before 5.0 SP3 allow remote authenticated users to execute arbi...Show more
Multiple unspecified vulnerabilities in the web management interface in Avaya Communication Manager (CM) 3.1 before 3.1.4 SP2, 4.0 before 4.0.3 SP1, and 5.0 before 5.0 SP3 allow remote authenticated users to execute arbitrary code via unknown attack vectors in the (1) Set Static Routes and (2) Backup History components.Show less
1Avaya
2Communication Manager
Sip Enablement Services
Apr 23, 2026
Aug 25, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
The remote management interface in SIP Enablement Services (SES) Server in Avaya SIP Enablement Services 5.0, and Communication Manager (CM) 5.0 on the S8300C with SES enabled, proceeds with Core router updates even when...Show more
The remote management interface in SIP Enablement Services (SES) Server in Avaya SIP Enablement Services 5.0, and Communication Manager (CM) 5.0 on the S8300C with SES enabled, proceeds with Core router updates even when a login is invalid, which allows remote attackers to cause a denial of service (messaging outage) or gain privileges via an update request.Show less
1Avaya
2Communication Manager
Sip Enablement Services
Apr 23, 2026
Aug 25, 2008
N/A· v4
N/A· v3
2.1 LOW· v2
The SIP Enablement Services (SES) Server in Avaya SIP Enablement Services 5.0, and Communication Manager (CM) 5.0 on the S8300C with SES enabled, writes account names and passwords to the (1) alarm and (2) system logs du...Show more
The SIP Enablement Services (SES) Server in Avaya SIP Enablement Services 5.0, and Communication Manager (CM) 5.0 on the S8300C with SES enabled, writes account names and passwords to the (1) alarm and (2) system logs during failed login attempts, which allows local users to obtain login credentials by reading these logs.Show less
1Avaya
1Messaging Storage Server
Apr 23, 2026
Jul 9, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple unspecified "input validation" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Storage Server (MSS) 3.x and 4.0, and possibly Communication Manager 3.1.x...Show more
Multiple unspecified "input validation" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Storage Server (MSS) 3.x and 4.0, and possibly Communication Manager 3.1.x, allow remote authenticated administrators to execute arbitrary commands as user vexvm via vectors related to (1) SFTP Remote Store configuration; (2) remote FTP storage settings; (3) name server lookup; (4) pinging another host; (5) TCP/IP Networking parameter configuration; (6) the external hosts configuration main page; (7) adding and changing external hosts; (8) Windows domain parameter configuration; (9) date, time, and NTP server configuration; (10) alarm settings; (11) the command line history form; (12) the maintenance form; and (13) the server events form.Show less
7Avaya
CanonicalDebian+4 more
15Communication Manager
Debian LinuxExpanded Meet Me Conferencing+12 more
Apr 23, 2026
Jul 9, 2008
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference...Show more
The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference of function pointers in (1) hamradio/6pack.c, (2) hamradio/mkiss.c, (3) irda/irtty-sir.c, (4) ppp_async.c, (5) ppp_synctty.c, (6) slip.c, (7) wan/x25_asy.c, and (8) wireless/strip.c in drivers/net/.Show less
1Avaya
2Message Networking
Messaging Storage Server
Apr 23, 2026
Nov 5, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
Unspecified vulnerability in the administrative interface in Avaya Messaging Storage Server (MSS) 3.1 before SP1, and Message Networking (MN) 3.1, allows remote attackers to cause a denial of service via unspecified vect...Show more
Unspecified vulnerability in the administrative interface in Avaya Messaging Storage Server (MSS) 3.1 before SP1, and Message Networking (MN) 3.1, allows remote attackers to cause a denial of service via unspecified vectors related to "input validation."Show less
1Avaya
1Voip Handset
Apr 23, 2026
Oct 18, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
Unspecified vulnerability in the Avaya VoIP Handset allows remote attackers to cause a denial of service (reboot) via crafted packets. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable...Show more
Unspecified vulnerability in the Avaya VoIP Handset allows remote attackers to cause a denial of service (reboot) via crafted packets. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.Show less
1Avaya
1Ip Soft Phone
Apr 23, 2026
Sep 19, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple buffer overflows in unspecified ActiveX controls in COM objects in Avaya IP Softphone R5.2 before SP3, and R6.0, allow remote attackers to execute arbitrary code via unspecified vectors.
1Avaya
14602sw Ip Phone
Apr 23, 2026
Jun 21, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Avaya 4602 SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware uses a constant media port number for calls, which allows remote attackers to cause a denial of service (audio quality loss) via a flood of...Show more
The Avaya 4602 SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware uses a constant media port number for calls, which allows remote attackers to cause a denial of service (audio quality loss) via a flood of packets to the RTP port.Show less
1Avaya
14602sw Ip Phone
Apr 23, 2026
Jun 21, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Avaya 4602 SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware allows remote attackers to cause a denial of service (device reboot) via a flood of packets to the BOOTP port (68/udp).
1Avaya
14602sw Ip Phone
Apr 23, 2026
Jun 21, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Avaya 4602SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware accepts SIP INVITE requests from arbitrary source IP addresses, which allows remote attackers to have an unspecified impact.
1Avaya
14602sw Ip Phone
Apr 23, 2026
Jun 21, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
The Avaya 4602SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware does not use the cnonce parameter in the Authorization header of SIP requests during MD5 digest authentication, which allows remote attackers...Show more
The Avaya 4602SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware does not use the cnonce parameter in the Authorization header of SIP requests during MD5 digest authentication, which allows remote attackers to conduct man-in-the-middle attacks and hijack or intercept communications.Show less
1Avaya
1One X
Apr 23, 2026
Jun 21, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in the Session Initiation Protocol (SIP) User Access Client (UAC) message parsing module in Avaya one-X Desktop Edition 2.1.0.70 and earlier allows remote attackers to cause a denial of service (call rece...Show more
Buffer overflow in the Session Initiation Protocol (SIP) User Access Client (UAC) message parsing module in Avaya one-X Desktop Edition 2.1.0.70 and earlier allows remote attackers to cause a denial of service (call reception outage) via a malformed SIP message.Show less
1Avaya
1One X
Apr 23, 2026
Jun 21, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
The Session Initiation Protocol (SIP) User Access Client (UAC) message parsing module in Avaya one-X Desktop Edition 2.1.0.70 and earlier allows remote attackers to cause a denial of service (device crash) via a malforme...Show more
The Session Initiation Protocol (SIP) User Access Client (UAC) message parsing module in Avaya one-X Desktop Edition 2.1.0.70 and earlier allows remote attackers to cause a denial of service (device crash) via a malformed SIP message.Show less
2Avaya
Microsoft
7Definity One Media Server
Media ServerS3400+4 more
Apr 23, 2026
Apr 30, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
Unspecified vulnerability in Microsoft Windows 2000, XP, and Server 2003 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors. NOTE: this information is based upon a vague pre-advisory...Show more
Unspecified vulnerability in Microsoft Windows 2000, XP, and Server 2003 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors. NOTE: this information is based upon a vague pre-advisory with no actionable information. However, the advisory is from a reliable source.Show less
2Avaya
Microsoft
10Definity One Media Server
IeInternet Explorer+7 more
Apr 23, 2026
Mar 30, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory c...Show more
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this issue might be a duplicate of CVE-2007-0038; if so, then use CVE-2007-0038 instead of this identifier.Show less
1Avaya
4S8300
S8500S8700+1 more
Apr 23, 2026
Mar 16, 2007
N/A· v4
N/A· v3
5.2 MEDIUM· v2
Apache Tomcat in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allows connections from external interfaces via port 8009, which exposes it to attacks from outside parties.
1Avaya
1Communication Manager
Apr 23, 2026
Mar 16, 2007
N/A· v4
N/A· v3
6.0 MEDIUM· v2
Unspecified maintenance web pages in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allow remote authenticated users to execute arbitrary commands via shell metacharacters in unspecified vectors (aka "shell...Show more
Unspecified maintenance web pages in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allow remote authenticated users to execute arbitrary commands via shell metacharacters in unspecified vectors (aka "shell command injection").Show less
1Avaya
4S8300
S8500S8700+1 more
Apr 23, 2026
Mar 9, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the login page in Avaya Communications Manager (CM) S87XX, S8500, and S8300 products before 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the Login f...Show more
Cross-site scripting (XSS) vulnerability in the login page in Avaya Communications Manager (CM) S87XX, S8500, and S8300 products before 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the Login field.Show less
2Avaya
Busybox
5Aura Application Enablement Services
Aura Sip Enablement ServicesBusybox+2 more
Apr 16, 2026
Apr 4, 2006
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.