imPC@ndo IT

Cisco vulnerabilities

6639 CVE

CVE-2020-3291
High 7.2

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execu…

cisco rv016_firmware · cisco rv042_firmware · cisco rv042g_firmware · cisco rv082_firmware · and 2 more
0.03EPSS
CVE-2020-3290
High 7.2

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execu…

cisco rv016_firmware · cisco rv042_firmware · cisco rv042g_firmware · cisco rv082_firmware · and 2 more
0.03EPSS
CVE-2020-3289
High 7.2

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execu…

cisco rv016_firmware · cisco rv042_firmware · cisco rv042g_firmware · cisco rv082_firmware · and 2 more
0.03EPSS
CVE-2020-3288
High 7.2

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execu…

cisco rv016_firmware · cisco rv042_firmware · cisco rv042g_firmware · cisco rv082_firmware · and 2 more
0.03EPSS
CVE-2020-3287
High 7.2

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execu…

cisco rv016_firmware · cisco rv042_firmware · cisco rv042g_firmware · cisco rv082_firmware · and 2 more
0.03EPSS
CVE-2020-3286
High 7.2

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execu…

cisco rv016_firmware · cisco rv042_firmware · cisco rv042g_firmware · cisco rv082_firmware · and 2 more
0.03EPSS
CVE-2013-1118
High 9.3

Stack-based buffer overflow in Cisco WebEx Recording Format (WRF) player T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28.8 allows remote attackers to execute arbitrary code via a crafted WRF file, aka Bug ID CSCuc27645.

cisco webex_recording_format_player
0.03EPSS
CVE-2012-3057
High 9.3

Heap-based buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 L through SP11 EP26, T27 LB through SP21 EP10, T27 LC before SP25 EP11, T27 LD before SP32 CP2, and T28 L10N before SP1 allows remote attackers to execute arbitrary code via a craf…

cisco webex_recording_format_player
0.03EPSS
CVE-2012-3055
High 9.3

Stack-based buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 L through SP11 EP26, T27 LB through SP21 EP10, T27 LC before SP25 EP11, T27 LD before SP32 CP2, and T28 L10N before SP1 allows remote attackers to execute arbitrary code via a cra…

cisco webex_recording_format_player
0.03EPSS
CVE-2012-3053
High 9.3

Buffer overflow in the Cisco WebEx Advanced Recording Format (ARF) player T27 L through SP11 EP26, T27 LB through SP21 EP10, T27 LC before SP25 EP11, T27 LD before SP32 CP2, and T28 L10N before SP1 allows remote attackers to execute arbitrary code via a crafte…

cisco webex_advanced_recording_format_player
0.03EPSS
CVE-2020-3332
High 8.8

A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Series Routers could allow an authenticated, remote attacker to inject arbitrary shell commands that are executed by an affected device. The vulnera…

cisco rv110w_wireless-n_vpn_firewall_firmware · cisco rv130_vpn_router_firmware · cisco rv130w_wireless-n_multifunction_vpn_router_firmware · cisco rv215w_wireless-n_vpn_router_firmware
0.03EPSS
CVE-2010-4686
High 7.8

CallManager Express (CME) on Cisco IOS before 15.0(1)XA1 does not properly handle SIP TRUNK traffic that contains rate bursts and a "peculiar" request size, which allows remote attackers to cause a denial of service (memory consumption) by sending this traffic…

cisco ios
0.03EPSS
CVE-2010-4683
High 7.8

Memory leak in Cisco IOS before 15.0(1)XA5 might allow remote attackers to cause a denial of service (memory consumption) by sending a crafted SIP REGISTER message over UDP, aka Bug ID CSCtg41733.

cisco ios
0.03EPSS
CVE-2009-5038
High 7.8

Cisco IOS before 15.0(1)XA does not properly handle IRC traffic during a specific time period after an initial reload, which allows remote attackers to cause a denial of service (device reload) via an attempted connection to a certain IRC server, related to a …

cisco ios
0.03EPSS
CVE-2022-20755
Critical 9.0

Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read/write privileges to the application to write file…

cisco telepresence_video_communication_server
0.03EPSS
CVE-2022-20754
Critical 9.0

Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read/write privileges to the application to write file…

cisco telepresence_video_communication_server
0.03EPSS
CVE-2018-0456
High 7.7

A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco NX-OS Software could allow an authenticated, remote attacker to cause the SNMP application of an affected device to restart unexpectedly. The vulnerability is due …

cisco nx-os
0.03EPSS
CVE-2017-12230
High 8.8

A vulnerability in the web-based user interface (web UI) of Cisco IOS XE 16.2 could allow an authenticated, remote attacker to elevate their privileges on an affected device. The vulnerability is due to incorrect default permission settings for new users who a…

cisco ios_xe
0.03EPSS
CVE-2006-4650
Low 2.6

Cisco IOS 12.0, 12.1, and 12.2, when GRE IP tunneling is used and the RFC2784 compliance fixes are missing, does not verify the offset field of a GRE packet during decapsulation, which leads to an integer overflow that references data from incorrect memory loc…

cisco ios
0.03EPSS
CVE-2013-3468
High 7.8

The Cisco Unified IP Phone 8945 with software 9.3(2) allows remote attackers to cause a denial of service (device hang) via a malformed PNG file, aka Bug ID CSCud04270.

cisco unified_ip_phone_8945 · cisco unified_ip_phone_firmware
0.03EPSS
CVE-2008-3798
High 7.8

Cisco IOS 12.4 allows remote attackers to cause a denial of service (device crash) via a normal, properly formed SSL packet that occurs during termination of an SSL session.

cisco ios
0.03EPSS
CVE-2004-1435
Medium 5.0

Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.6(0) and 4.6(1), 4.5(x), 4.1(0) to 4.1(3), 4.0(0) to 4.0(2), and earlier versions, allows remote attackers to cause a denial of service (control card reset) via a large number of T…

cisco optical_networking_systems_software
0.03EPSS
CVE-2004-0352
Medium 5.0

Cisco 11000 Series Content Services Switches (CSS) running WebNS 5.0(x) before 05.0(04.07)S, and 6.10(x) before 06.10(02.05)S allow remote attackers to cause a denial of service (device reset) via a malformed packet to UDP port 5002.

cisco content_services_switch_11000 · cisco content_services_switch_11050 · cisco content_services_switch_11150 · cisco content_services_switch_11800
0.03EPSS
CVE-2018-0417
High 7.8

A vulnerability in TACACS authentication with Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to perform certain operations within the GUI that are not normally available to that user on the CLI. The vulnerability is d…

cisco wireless_lan_controller · cisco wireless_lan_controller_software
0.03EPSS
CVE-2007-4291
High 7.1

Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service via (1) a malformed MGCP packet, which causes a device hang, aka CSCsf08998; a malformed H.323 packet, which causes a device crash, as identified by (2) CSCsi60004 with Proxy Unre…

cisco ios
0.03EPSS