9.3
CVSSv2

CVE-2006-5277

Published: 15/07/2007 Updated: 17/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Off-by-one error in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) prior to 20070711 allow remote malicious users to execute arbitrary code via a crafted packet that triggers a heap-based buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified communications manager

cisco unified callmanager

cisco unified callmanager 5.0