10

CVE-2006-5278

Integer overflow in the Real-Time Information Server (RIS) Data Collector service (RisDC.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via crafted packets, resulting in a heap-based buffer overflow.

Data is provided by the National Vulnerability Database (NVD)
CiscoUnified Callmanager Version >= 3.3 <= 3.3\(5\)sr2
CiscoUnified Callmanager Version >= 4.1 <= 4.1\(3\)sr4
CiscoUnified Callmanager Version >= 4.2 <= 4.2\(3\)sr1
CiscoUnified Callmanager Version >= 5.1 <= 5.1\(2\)
CiscoUnified Callmanager Version5.0
CiscoUnified Communications Manager Version >= 4.3 <= 4.3\(1\)
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 9.73% 0.921
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C