VYPR

Unified IP Phone 9951

by Cisco Systems, Inc.

CVEs (7)

  • CVE-2014-0658Jan 10, 2014
    risk 0.00cvss epss 0.03

    Cisco 9900 Unified IP phones allow remote attackers to cause a denial of service (unregistration) via a crafted SIP header, aka Bug ID CSCul24898.

  • CVE-2013-6685Nov 13, 2013
    risk 0.00cvss epss 0.00

    The firmware on Cisco Unified IP phones 8961, 9951, and 9971 uses weak permissions for memory block devices, which allows local users to gain privileges by mounting a device with a setuid file in its filesystem, aka Bug ID CSCui04382.

  • CVE-2013-5533Oct 11, 2013
    risk 0.00cvss epss 0.00

    The image-upgrade functionality on Cisco 9900 Unified IP phones allows local users to gain privileges by placing shell commands in an unspecified parameter, aka Bug ID CSCuh10334.

  • CVE-2013-5532Oct 11, 2013
    risk 0.00cvss epss 0.02

    Buffer overflow in the web-application interface on Cisco 9900 IP phones allows remote attackers to cause a denial of service (webapp interface outage) via long values in unspecified fields, aka Bug ID CSCuh10343.

  • CVE-2013-5526Oct 10, 2013
    risk 0.00cvss epss 0.02

    Cisco 9900 fourth-generation IP phones do not properly perform SDP negotiation, which allows remote attackers to cause a denial of service (device reboot) via crafted SDP packets, aka Bug ID CSCuf06698.

  • CVE-2013-3426Jul 18, 2013
    risk 0.00cvss epss 0.01

    The Serviceability servlet on Cisco 9900 IP phones does not properly restrict paths, which allows remote attackers to read arbitrary files by specifying a pathname in a file request, aka Bug ID CSCuh52810.

  • CVE-2007-6190Nov 30, 2007
    risk 0.00cvss epss 0.01

    The HTTP daemon in the Cisco Unified IP Phone, when the Extension Mobility feature is enabled, allows remote authenticated users of other phones associated with the same CUCM server to eavesdrop on the physical environment via a CiscoIPPhoneExecute message containing a URL…