CVE-2021-1469
24.03.2021, 20:15
Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for MacOS, and Cisco Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system with elevated privileges, access sensitive information, intercept protected network traffic, or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory.Enginsight
Vendor | Product | Version |
---|---|---|
cisco | jabber | 𝑥 < 12.1.5 |
cisco | jabber | 12.5.0 ≤ 𝑥 < 12.5.4 |
cisco | jabber | 12.6.0 ≤ 𝑥 < 12.6.5 |
cisco | jabber | 12.7.0 ≤ 𝑥 < 12.7.4 |
cisco | jabber | 12.8.0 ≤ 𝑥 < 12.8.5 |
cisco | jabber | 12.9.0 ≤ 𝑥 < 12.9.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-170 - Improper Null TerminationThe software does not terminate or incorrectly terminates a string or array with a null character or equivalent terminator.
- CWE-20 - Improper Input ValidationThe product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.