CyberSec.Space Logo
返回 CVE 浏览器

CVE-2006-5277

CRITICAL
9.3
CVSS Severity Score
EPSS Score0.1940%
EPSS Percentile39.27th
Published2007年7月15日
Last Modified2026年4月23日

Vulnerability Description

Off-by-one error in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via a crafted packet that triggers a heap-based buffer overflow.

Affected Platforms (CPE)

📦
Cisco

Unified Callmanager

>= 3.3 and <= 3.3\(5\)sr2
📦
Cisco

Unified Callmanager

>= 4.1 and <= 4.1\(3\)sr4
📦
Cisco

Unified Callmanager

>= 4.2 and <= 4.2\(3\)sr1
📦
Cisco

Unified Callmanager

= 5.0
📦
Cisco

Unified Communications Manager

>= 4.3 and <= 4.3\(1\)
📦
Cisco

Unified Communications Manager

>= 5.1 and <= 5.1\(1\)

References & Advisories

相关漏洞威胁