VendorsAvayaip_officeall versions
Vulnerabilities

Avaya IP Office

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2024-4196
Avaya IP Office Web Control RCE Vulnerability
Published 2024-06-25 · Modified
10.0EPSS 0.006
CVE-2024-4197
Avaya IP Office One-X Portal File Upload Vulnerability
Published 2024-06-25 · Analyzed
9.9EPSS 0.008
CVE-2017-11309
Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response.
Published 2017-11-09 · Modified
9.61 PoCEPSS 0.094
CVE-2018-15610
Improper access controls in IP Office one-X Portal
Published 2018-09-12 · Modified
9.0EPSS 0.018
CVE-2021-25657
Avaya IP Office Privilege Escalation Vulnerability
Published 2022-09-02 · Modified
7.8EPSS 0.003
CVE-2016-5285
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
Published 2019-11-15 · Modified
7.5EPSS 0.023
CVE-2019-7005
Unauthenticated Information Disclosure Vulnerability in IP Office
Published 2020-08-07 · Modified
7.5EPSS 0.012
CVE-2018-15614
IP Office one-X Portal XSS
Published 2019-01-23 · Modified
6.8EPSS 0.006
CVE-2020-7030
IPO Information Disclosure
Published 2020-06-03 · Modified
5.51 PoCEPSS 0.010