Avaya's vulnerability footprint spans a modestly sized portfolio of enterprise communication and messaging platforms that sit centrally in business telephony, contact center, and unified messaging infrastructure. The vendor's disclosures frequently acquire public exploit code, reflecting the operational importance and accessibility of its Communication Manager, Modular Messaging, and S-series appliances to attackers seeking to disrupt or surveil corporate voice and messaging environments. The recurring weakness classes center on input-handling and information-disclosure issues—including cross-site scripting, improper input validation, and exposure of sensitive data—that are characteristic of complex, web-accessible administration interfaces and embedded network services. Defenders should prioritize patching these platforms, particularly internet-exposed instances and those managing sensitive call and message traffic; live exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Avaya, Inc. over time
Of all the CVEs published by Avaya, Inc. as a CNA, 100.0% affect products that Avaya, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Avaya, Inc., 32.4% are self-published by Avaya, Inc. as a CNA.
Signals from CVEs in this vendor scope (139 CVEs).
139 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-3811HIGH Unrestricted file upload vulnerability in ImageUpload.ashx in the Wallboard application in Avaya IP Office Customer Call Reporter 7.0 before 7.0.5.8 Q1 2012 Maintenance Release and | Jul 3, 2012 | 10.0 | 80 | NO | YES |
CVE-2004-1050HIGH Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as | Dec 31, 2004 | 10.0 | 77 | NO | YES |
CVE-2007-1765HIGH Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malfo | Mar 30, 2007 | 9.3 | 73 | NO | YES |
CVE-2004-0493MEDIUM The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error lead | Aug 6, 2004 | 6.4 | 72 | NO | YES |
CVE-2004-0212HIGH Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via | Aug 6, 2004 | 10.0 | 70 | NO | YES |
CVE-2004-0842HIGH Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain ma | Dec 23, 2004 | 7.5 | 61 | NO | YES |
CVE-2004-0841MEDIUM Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, ak | Dec 23, 2004 | 5.0 | 54 | NO | YES |
CVE-2004-0595MEDIUM The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows d | Jul 27, 2004 | 6.8 | 54 | NO | YES |
CVE-2004-0594MEDIUM The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute | Jul 27, 2004 | 5.1 | 51 | NO | YES |
CVE-2004-0201HIGH Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrar | Aug 6, 2004 | 10.0 | 48 | NO | NO |
Signals from CVEs in this vendor scope (139 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Avaya, Inc..
Media articles that mention a CVE ID that affects a product developed by Avaya, Inc. — matched by CVE ID, not by vendor name.