NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
79671 | CVE-2002-0671 | Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the integrity of the applications, which could allow remote attackers to install Trojan horse applications via DNS spoofing. | 2 | 7.5 | High | 2017-01-05 | 2008-09-10 | View | |
79672 | CVE-2002-0672 | Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to restore the phone to factory defaults without authentication via a menu option, which sets the administrator password to null. | 2 | 4.6 | Medium | 2017-01-05 | 2008-09-05 | View | |
79673 | CVE-2002-0673 | The enrollment process for Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 allows attackers with physical access to the phone to log out the current user and re-register the phone using MyPingtel Sign-In to gain remote access and perform unauthorized actions. | 2 | 4.6 | Medium | 2017-01-05 | 2008-09-05 | View | |
79674 | CVE-2002-0674 | Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not "time out" an inactive administrator session, which could allow other users to perform administrator actions if the administrator does not explicitly end the authentication. | 2 | 7.2 | High | 2017-01-05 | 2011-03-07 | View | |
79675 | CVE-2002-0675 | Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 does not require administrative privileges to perform a firmware upgrade, which allows unauthorized users to upgrade the phone. | 2 | 4.6 | Medium | 2017-01-05 | 2008-09-10 | View |
Page 1001 of 17672, showing 5 records out of 88360 total, starting on record 5001, ending on 5005