imPC@ndo IT

Cisco vulnerabilities

6639 CVE

CVE-2010-4670
High 7.8

The Neighbor Discovery (ND) protocol implementation in the IPv6 stack on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2(3) and earlier, and Cisco PIX Security Appliances devices, allows remote attackers to cause a denial of serv…

cisco 5500_series_adaptive_security_appliance · cisco adaptive_security_appliance_software · cisco asa_5500 · cisco pix_security_appliance
0.03EPSS
CVE-2008-3806
High 8.5

Cisco IOS 12.0 through 12.4 on Cisco 10000, uBR10012 and uBR7200 series devices handles external UDP packets that are sent to 127.0.0.0/8 addresses intended for IPC communication within the device, which allows remote attackers to cause a denial of service (de…

cisco ios
0.03EPSS
CVE-2004-1436
High 7.5

The Transaction Language 1 (TL1) login interface in Cisco ONS 15327 4.6(0) and 4.6(1) and 15454 and 15454 SDH 4.6(0) and 4.6(1), when a user account is configured with a blank password, allows remote attackers to gain unauthorized access by logging in with a p…

cisco optical_networking_systems_software
0.03EPSS
CVE-2008-3813
High 7.8

Unspecified vulnerability in Cisco IOS 12.2 and 12.4, when the L2TP mgmt daemon process is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted L2TP packet.

cisco ios
0.03EPSS
CVE-2008-3799
High 7.8

Memory leak in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4, when VoIP is configured, allows remote attackers to cause a denial of service (memory consumption and voice-service outage) via unspecified valid SIP messages.

cisco ios
0.03EPSS
CVE-2019-15961
High 7.5

A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to inefficie…

canonical ubuntu_linux · cisco email_security_appliance_firmware · clamav clamav · debian debian_linux
0.03EPSS
CVE-2014-3299
Medium 6.8

Cisco IOS allows remote authenticated users to cause a denial of service (device reload) via malformed IPsec packets, aka Bug ID CSCui79745.

cisco ios
0.03EPSS
CVE-2017-12249
Critical 9.1

A vulnerability in the Traversal Using Relay NAT (TURN) server included with Cisco Meeting Server (CMS) could allow an authenticated, remote attacker to gain unauthenticated or unauthorized access to components of or sensitive information in an affected system…

cisco meeting_server
0.03EPSS
CVE-2017-3858
High 8.8

A vulnerability in the web framework of Cisco IOS XE Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation of HTTP parameters suppli…

cisco ios_xe
0.03EPSS
CVE-2004-0551
Medium 5.0

Cisco CatOS 5.x before 5.5(20) through 8.x before 8.2(2) and 8.3(2)GLX, as used in Catalyst switches, allows remote attackers to cause a denial of service (system crash and reload) by sending invalid packets instead of the final ACK portion of the three-way ha…

cisco catalyst_2901 · cisco catalyst_2902 · cisco catalyst_2926 · cisco catalyst_2926f · and 20 more
0.03EPSS
CVE-2014-3333
High 9.0

The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticated users to obtain privileged access by conducting an "HTTP Intercept" attack and leveraging the ability to read files within the context of the web-server user account, aka Bug ID…

cisco unity_connection
0.03EPSS
CVE-1999-0775
High 10.0

Cisco Gigabit Switch routers running IOS allow remote attackers to forward unauthorized packets due to improper handling of the "established" keyword in an access list.

cisco ios
0.03EPSS
CVE-2012-5417
High 10.0

Cisco Prime Data Center Network Manager (DCNM) before 6.1(1) does not properly restrict access to certain JBoss MainDeployer functionality, which allows remote attackers to execute arbitrary commands via JBoss Application Server Remote Method Invocation (RMI) …

cisco prime_data_center_network_manager
0.03EPSS
CVE-2014-2133
High 9.3

Buffer overflow in Cisco Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T28 before T28.12, and T29 before T29.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a craf…

cisco webex_advanced_recording_format_player · cisco webex_recording_format_player
0.03EPSS
CVE-2013-1119
High 9.3

Buffer overflow in Cisco WebEx Recording Format (WRF) player T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted DHT index…

cisco webex_recording_format_player
0.03EPSS
CVE-2013-1117
High 9.3

Buffer overflow in the exception handler in Cisco WebEx Recording Format (WRF) player T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption…

cisco webex_recording_format_player
0.03EPSS
CVE-2013-1116
High 9.3

Buffer overflow in Cisco WebEx Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28.8 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a cra…

cisco webex_advanced_recording_format_player
0.03EPSS
CVE-2013-1115
High 9.3

Buffer overflow in Cisco WebEx Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted …

cisco webex_advanced_recording_format_player
0.03EPSS
CVE-2012-3056
High 9.3

Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 L through SP11 EP26, T27 LB through SP21 EP10, T27 LC before SP25 EP11, T27 LD before SP32 CP2, and T28 L10N before SP1 allows remote attackers to execute arbitrary code or cause a denial of …

cisco webex_recording_format_player
0.03EPSS
CVE-2019-12689
High 8.8

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system of an affected device. The vulnerability is due…

cisco secure_firewall_management_center
0.03EPSS
CVE-2014-3338
High 8.5

The CTIManager module in Cisco Unified Communications Manager (CM) 10.0(1), when single sign-on is enabled, does not properly validate Kerberos SSO tokens, which allows remote authenticated users to gain privileges and execute arbitrary commands via crafted to…

cisco unified_communications_manager
0.03EPSS
CVE-2019-1698
Medium 4.9

A vulnerability in the web-based user interface of Cisco Internet of Things Field Network Director (IoT-FND) Software could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The vulnerability is du…

cisco iot_field_network_director
0.03EPSS
CVE-2017-12236
Critical 9.8

A vulnerability in the implementation of the Locator/ID Separation Protocol (LISP) in Cisco IOS XE 3.2 through 16.5 could allow an unauthenticated, remote attacker using an x tunnel router to bypass authentication checks performed when registering an Endpoint …

cisco ios_xe
0.03EPSS
CVE-2016-6464
High 7.5

A vulnerability in the web management interface of the Cisco Unified Communications Manager IM and Presence Service could allow an unauthenticated, remote attacker to view information on web pages that should be restricted. More Information: CSCva49629. Known …

cisco unified_communications_manager_im_and_presence_service
0.03EPSS
CVE-2010-0595
High 10.0

Cisco Mediator Framework 1.5.1 before 1.5.1.build.14-eng, 2.2 before 2.2.1.dev.1, and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediator NBM-2400 and NBM-4800 and the Richards-Zeta Mediator 2500 has a default password for the administrative user…

cisco mediator_framework
0.03EPSS