Avaya

Aura System Manager

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Veröffentlicht 08.08.2024 16:15:09
  • Zuletzt bearbeitet 11.09.2024 15:03:06

A SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privileges to execute arbitrary queries against the Avaya Aura System Manager database.  Affected versions include 10.1.x.x and 10.2.x....

  • EPSS 0.06%
  • Veröffentlicht 08.08.2024 16:15:09
  • Zuletzt bearbeitet 01.10.2025 02:15:33

An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administrative privileges to read arbitrary files on the system. Affected versions include 10.1.x.x and 10.2.x....

Exploit
  • EPSS 0.48%
  • Veröffentlicht 13.11.2020 01:15:11
  • Zuletzt bearbeitet 21.11.2024 05:36:31

An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. Affected versions of Avaya WebLM i...

  • EPSS 0.65%
  • Veröffentlicht 15.11.2019 16:15:10
  • Zuletzt bearbeitet 21.11.2024 02:53:59

A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.

Exploit
  • EPSS 3.82%
  • Veröffentlicht 30.09.2010 15:00:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assign...

  • EPSS 0.06%
  • Veröffentlicht 21.09.2010 18:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive in...

  • EPSS 0.03%
  • Veröffentlicht 08.09.2010 20:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or cause a denial of service (system crash) via unspecified vectors.

  • EPSS 0.05%
  • Veröffentlicht 08.09.2010 20:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer derefe...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 16.11.2009 19:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.