CyberSec.Space Logo
Back to CVE Browser

CVE-2006-5277

CRITICAL
9.3
CVSS Severity Score
EPSS Score0.1940%
EPSS Percentile39.27th
PublishedJul 15, 2007
Last ModifiedApr 23, 2026

Vulnerability Description

Off-by-one error in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via a crafted packet that triggers a heap-based buffer overflow.

Affected Platforms (CPE)

πŸ“¦
Cisco

Unified Callmanager

>= 3.3 and <= 3.3\(5\)sr2
πŸ“¦
Cisco

Unified Callmanager

>= 4.1 and <= 4.1\(3\)sr4
πŸ“¦
Cisco

Unified Callmanager

>= 4.2 and <= 4.2\(3\)sr1
πŸ“¦
Cisco

Unified Callmanager

= 5.0
πŸ“¦
Cisco

Unified Communications Manager

>= 4.3 and <= 4.3\(1\)
πŸ“¦
Cisco

Unified Communications Manager

>= 5.1 and <= 5.1\(1\)

References & Advisories

Related Vulnerabilities