imPC@ndo EN

Vulnerabilità Cisco

6639 CVE

CVE-2017-12263
Alta 7.5

A vulnerability in the web interface of Cisco License Manager software could allow an unauthenticated, remote attacker to download and view files within the application that should be restricted, aka Directory Traversal. The issue is due to improper sanitizati…

cisco license_manager
0.11EPSS
CVE-2014-2127
Alta 8.5

Cisco Adaptive Security Appliance (ASA) Software 8.x before 8.2(5.48), 8.3 before 8.3(2.40), 8.4 before 8.4(7.9), 8.6 before 8.6(1.13), 9.0 before 9.0(4.1), and 9.1 before 9.1(4.3) does not properly process management-session information during privilege valid…

cisco adaptive_security_appliance_software
0.11EPSS
CVE-2010-3269
Alta 9.3

Multiple stack-based buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to execute arbitrary code via a crafted (1) .wrf or (2) .arf file, re…

cisco webex_advanced_recording_format_player · cisco webex_recording_format_player
0.11EPSS
CVE-2022-20780
Critica 9.9

Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the…

cisco enterprise_nfv_infrastructure_software
0.11EPSS
CVE-2023-20189
Alta 8.6

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected …

cisco business_250-16p-2g_firmware · cisco business_250-16t-2g_firmware · cisco business_250-24fp-4g_firmware · cisco business_250-24fp-4x_firmware · e altri 225
0.11EPSS
CVE-2007-0105
Alta 7.5

Stack-based buffer overflow in the CSAdmin service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers to execute arbitrary code via a crafted HTTP GET request.

cisco secure_access_control_server
0.11EPSS
CVE-2022-20777
Critica 9.9

Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the…

cisco enterprise_nfv_infrastructure_software
0.11EPSS
CVE-2011-2738
Alta 10.0

Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before 8.6, as used in Unified Operations Manager before 8.6 and CiscoWorks LAN Management Solution 3.x and 4.x before 4.1; and multiple EMC Ionix products including Application Connectivity…

cisco ciscoworks_lan_management_solution · cisco unified_operations_manager · cisco unified_service_monitor · emc ionix_acm · e altri 2
0.11EPSS
CVE-2019-1674
Alta 7.8

A vulnerability in the update service of Cisco Webex Meetings Desktop App and Cisco Webex Productivity Tools for Windows could allow an authenticated, local attacker to execute arbitrary commands as a privileged user. The vulnerability is due to insufficient v…

cisco webex_meetings · cisco webex_meetings_online · cisco webex_productivity_tools
0.11EPSS
CVE-2011-3271
Alta 10.0

Unspecified vulnerability in the Smart Install functionality in Cisco IOS 12.2 and 15.1 allows remote attackers to execute arbitrary code or cause a denial of service (device crash) via crafted TCP packets to port 4786, aka Bug ID CSCto10165.

cisco ios
0.11EPSS
CVE-2017-6640
Critica 9.8

A vulnerability in Cisco Prime Data Center Network Manager (DCNM) Software could allow an unauthenticated, remote attacker to log in to the administrative console of a DCNM server by using an account that has a default, static password. The account could be gr…

cisco prime_data_center_network_manager
0.11EPSS
CVE-2011-2040
Alta 9.3

The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.5.3041, and 3.0.x before 3.0.629, on Linux and Mac OS X downloads a client executable file (vpndownloader.exe) without verifying its authenticity, which…

cisco anyconnect_secure_mobility_client
0.11EPSS
CVE-2019-1943
Media 4.7

A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Switches software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of the par…

cisco sf200-24_firmware · cisco sf200-24fp_firmware · cisco sf200-24p_firmware · cisco sf200-48_firmware · e altri 53
0.11EPSS
CVE-2006-0354
Media 5.5

Cisco IOS before 12.3-7-JA2 on Aironet Wireless Access Points (WAP) allows remote authenticated users to cause a denial of service (termination of packet passing or termination of client connections) by sending the management interface a large number of spoofe…

cisco aironet_ap1100 · cisco aironet_ap1130ag · cisco aironet_ap1200 · cisco aironet_ap1230ag · e altri 4
0.10EPSS
CVE-2003-1096
Alta 10.0

The Cisco LEAP challenge/response authentication mechanism uses passwords in a way that is susceptible to dictionary attacks, which makes it easier for remote attackers to gain privileges via brute force password guessing attacks.

cisco leap
0.10EPSS
CVE-2022-20779
Critica 9.9

Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the…

cisco enterprise_nfv_infrastructure_software
0.10EPSS
CVE-2014-0683
Alta 10.0

The web management interface on the Cisco RV110W firewall with firmware 1.2.0.9 and earlier, RV215W router with firmware 1.1.0.5 and earlier, and CVR100W router with firmware 1.0.1.19 and earlier does not prevent replaying of modified authentication requests, …

cisco cvr100w · cisco cvr100w_firmware · cisco rv110w · cisco rv110w_firmware · e altri 2
0.10EPSS
CVE-2004-0112
Media 5.0

The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SS…

4d webstar · apple mac_os_x · apple mac_os_x_server · avaya converged_communications_server · e altri 61
0.10EPSS
CVE-2011-1613
Alta 7.8

Unspecified vulnerability in Cisco Wireless LAN Controller (WLC) software 6.0 before 6.0.200.0, 7.0 before 7.0.98.216, and 7.0.1xx before 7.0.112.0 allows remote attackers to cause a denial of service (device reload) via a sequence of ICMP packets, aka Bug ID …

cisco wireless_lan_controller_software
0.10EPSS
CVE-2023-20078
Critica 9.8

Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. For more information about these vulnerabilities, …

cisco ip_phone_6825_firmware · cisco ip_phone_6841_firmware · cisco ip_phone_6851_firmware · cisco ip_phone_6861_firmware · e altri 13
0.10EPSS
CVE-2023-20079
Critica 9.8

Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. For more information about these vulnerabilities, …

cisco ip_phone_6825_firmware · cisco ip_phone_6841_firmware · cisco ip_phone_6851_firmware · cisco ip_phone_6861_firmware · e altri 17
0.10EPSS
CVE-2001-0375
Media 5.0

Cisco PIX Firewall 515 and 520 with 5.1.4 OS running aaa authentication to a TACACS+ server allows remote attackers to cause a denial of service via a large number of authentication requests.

cisco pix_firewall_515 · cisco pix_firewall_520
0.10EPSS
CVE-2023-20161
Alta 8.6

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected …

cisco business_250-16p-2g_firmware · cisco business_250-16t-2g_firmware · cisco business_250-24fp-4g_firmware · cisco business_250-24fp-4x_firmware · e altri 225
0.10EPSS
CVE-2023-20160
Alta 8.6

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected …

cisco business_250-16p-2g_firmware · cisco business_250-16t-2g_firmware · cisco business_250-24fp-4g_firmware · cisco business_250-24fp-4x_firmware · e altri 225
0.10EPSS
CVE-2023-20159
Alta 8.6

Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected …

cisco business_250-16p-2g_firmware · cisco business_250-16t-2g_firmware · cisco business_250-24fp-4g_firmware · cisco business_250-24fp-4x_firmware · e altri 225
0.10EPSS