Avaya

Ip Office

9 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.41%
  • Published 25.06.2024 04:15:17
  • Last modified 21.01.2025 14:31:21

An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component. Affected versions include all versions prior to 11.1.3.1.

  • EPSS 0.61%
  • Published 25.06.2024 04:15:16
  • Last modified 01.10.2025 02:15:33

An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially crafted web request to the Web Control component. Affected versions include all versions prior to 11.1.3.1...

Exploit
  • EPSS 0.11%
  • Published 02.09.2022 01:15:07
  • Last modified 21.11.2024 05:55:14

A privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially allow a local user to escalate privileges. This issue affects Admin Lite and USB Creator 11.1 Feature Pack 2 Service Pack 1 and ear...

  • EPSS 0.42%
  • Published 07.08.2020 22:15:12
  • Last modified 21.11.2024 04:47:24

A vulnerability was discovered in the web interface component of IP Office that may potentially allow a remote, unauthenticated user with network access to gain sensitive information. Affected versions of IP Office include: 9.x, 10.0 through 10.1.0.7...

  • EPSS 0.28%
  • Published 04.06.2020 00:15:10
  • Last modified 21.11.2024 05:36:30

A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user to gain unauthorized access to the component. Affected versions of IP Office include: 9.x, 10.0 throug...

  • EPSS 0.65%
  • Published 15.11.2019 16:15:10
  • Last modified 21.11.2024 02:53:59

A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.

  • EPSS 0.2%
  • Published 23.01.2019 17:29:00
  • Last modified 21.11.2024 03:51:10

A vulnerability in the one-x Portal component of IP Office could allow an authenticated user to perform stored cross site scripting attacks via fields in the Conference Scheduler Service that could affect other application users. Affected versions of...

  • EPSS 0.62%
  • Published 12.09.2018 21:29:00
  • Last modified 21.11.2024 03:51:10

A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. Affected versions of Avaya IP Office include 9.1 through 9.1 SP12, 10.0 through 10.0 SP7, and 10.1 thr...

Exploit
  • EPSS 28.59%
  • Published 10.11.2017 02:29:16
  • Last modified 20.04.2025 01:37:25

Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response.