Mitel

Micollab

49 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.36%
  • Veröffentlicht 18.12.2020 08:15:14
  • Zuletzt bearbeitet 21.11.2024 05:18:14

The AWV portal of Mitel MiCollab before 9.2 could allow an attacker to gain access to conference information by sending arbitrary code due to improper input validation, aka XSS. Successful exploitation could allow an attacker to view user conference ...

  • EPSS 0.29%
  • Veröffentlicht 18.12.2020 08:15:14
  • Zuletzt bearbeitet 21.11.2024 05:21:02

The online help portal of Mitel MiCollab before 9.2 could allow an attacker to redirect a user to an unauthorized website by executing malicious script due to insufficient access control.

  • EPSS 0.69%
  • Veröffentlicht 26.08.2020 18:15:10
  • Zuletzt bearbeitet 21.11.2024 05:02:01

The SAS portal of Mitel MiCollab before 9.1.3 could allow an attacker to access user data by performing a header injection in HTTP responses, due to the improper handling of input parameters. A successful exploit could allow an attacker to access use...

  • EPSS 0.28%
  • Veröffentlicht 26.08.2020 18:15:10
  • Zuletzt bearbeitet 21.11.2024 05:01:48

The Mitel MiCollab application before 9.1.332 for iOS could allow an unauthorized user to access restricted files and folders due to insufficient access control. An exploit requires a rooted iOS device, and (if successful) could allow an attacker to ...

  • EPSS 0.75%
  • Veröffentlicht 02.03.2020 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:34:39

A cross-site scripting (XSS) vulnerability in the web conferencing component of the Mitel MiCollab application before 9.0.15 for Android could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insuffici...

  • EPSS 0.34%
  • Veröffentlicht 12.11.2019 14:15:11
  • Zuletzt bearbeitet 21.11.2024 03:56:40

A vulnerability in the web conference chat component of MiCollab, versions 7.3 PR6 (7.3.0.601) and earlier, and 8.0 (8.0.0.40) through 8.0 SP2 FP2 (8.0.2.202), and MiVoice Business Express versions 7.3 PR3 (7.3.1.302) and earlier, and 8.0 (8.0.0.40) ...

  • EPSS 0.78%
  • Veröffentlicht 29.05.2019 17:29:00
  • Zuletzt bearbeitet 21.11.2024 04:22:20

MiCollab 7.3 PR2 (7.3.0.204) and earlier, 7.2 (7.2.2.13) and earlier, and 7.1 (7.1.0.57) and earlier and MiCollab AWV 6.3 (6.3.0.103), 6.2 (6.2.2.8), 6.1 (6.1.0.28), 6.0 (6.0.0.61), and 5.0 (5.0.5.7) have a Command Execution Vulnerability. Successful...

Exploit
  • EPSS 44.99%
  • Veröffentlicht 22.05.2018 12:29:00
  • Zuletzt bearbeitet 21.11.2024 04:05:48

Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access vi...

Warnung Exploit
  • EPSS 94.48%
  • Veröffentlicht 07.04.2014 22:55:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer ov...