imPC@ndo EN

Vulnerabilità Cisco

6642 CVE

CVE-2024-20352
Media 4.9

A vulnerability in Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a directory traversal attack, which could allow the attacker to perform arbitrary actions on an affected device. This vulnerability is due to insufficient pro…

cisco emergency_responder
0.01EPSS
CVE-2017-3885
Media 5.9

A vulnerability in the detection engine reassembly of Secure Sockets Layer (SSL) packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition because the Snort process consumes a high …

cisco secure_firewall_management_center
0.01EPSS
CVE-2018-0404
Alta 7.5

A vulnerability in the web framework code for Cisco RV180W Wireless-N Multifunction VPN Router and Small Business RV Series RV220W Wireless Network Security Firewall could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The attacker…

cisco rv180w_wireless-n_multifunction_vpn_router · cisco rv220w_wireless_network_security_firewall
0.01EPSS
CVE-2010-2629
Alta 7.5

The Cisco Content Services Switch (CSS) 11500 with software 8.20.4.02 and the Application Control Engine (ACE) 4710 with software A2(3.0) do not properly handle LF header terminators in situations where the GET line is terminated by CRLF, which allows remote a…

cisco ace_4710 · cisco content_services_switch_11500
0.01EPSS
CVE-2009-0622
Alta 9.0

Unspecified vulnerability in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.2) and Cisco ACE 4710 Application Control Engine Appliance before A1(8a) allows remote authenticated users to execute arbitrary ope…

cisco ace_4710 · cisco application_control_engine_module
0.01EPSS
CVE-2016-1471
Media 6.1

Cross-site scripting (XSS) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuz76232.

cisco small_business_220_series_smart_plus_switches
0.01EPSS
CVE-2011-4012
Alta 9.3

Cisco IOS 12.0, 15.0, and 15.1, when a Policy Feature Card 3C (PFC3C) is used, does not create a fragment entry during processing of an ICMPv6 ACL, which has unspecified impact and remote attack vectors, aka Bug ID CSCtj90091.

cisco ios
0.01EPSS
CVE-2013-5534
Media 4.0

Directory traversal vulnerability in the attachment service in the Voice Message Web Service (aka VMWS or Cisco Unity Web Service) in Cisco Unity Connection allows remote authenticated users to create files, and consequently execute arbitrary JSP code, via a c…

cisco unity_connection
0.01EPSS
CVE-2019-1927
Alta 7.8

Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected software…

cisco webex_business_suite · cisco webex_meetings_online · cisco webex_meetings_server
0.01EPSS
CVE-2019-1924
Alta 7.8

Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected software…

cisco webex_business_suite · cisco webex_meetings_online · cisco webex_meetings_server
0.01EPSS
CVE-2013-1100
Media 5.4

The HTTP server in Cisco IOS on Catalyst switches does not properly handle TCP socket events, which allows remote attackers to cause a denial of service (device crash) via crafted packets on TCP port (1) 80 or (2) 443, aka Bug ID CSCuc53853.

cisco ios
0.01EPSS
CVE-2016-1378
Media 5.3

Cisco IOS before 15.2(2)E1 on Catalyst switches allows remote attackers to obtain potentially sensitive software-version information via a request to the Network Mobility Services Protocol (NMSP) port, aka Bug ID CSCum62591.

cisco ios
0.01EPSS
CVE-2016-1316
Media 5.3

Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7, as used in conjunction with Jabber Guest, allows remote attackers to obtain sensitive call-statistics information via a direct request to an unspecified URL, aka Bug ID CSCux73362.

cisco telepresence_video_communication_server_software
0.01EPSS
CVE-2002-1447
Alta 7.2

Buffer overflow in the vpnclient program for UNIX VPN Client before 3.5.2 allows local users to gain administrative privileges via a long profile name in a connect argument.

cisco vpn_client
0.01EPSS
CVE-2022-20798
Critica 9.8

A vulnerability in the external authentication functionality of Cisco Secure Email and Web Manager, formerly known as Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass …

cisco email_security_appliance · cisco secure_email_and_web_manager
0.01EPSS
CVE-2017-6708
Critica 9.8

A vulnerability in the symbolic link (symlink) creation functionality of the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to read sensitive files or execute malicious code on an affected system. The vulner…

cisco ultra_services_framework
0.01EPSS
CVE-2015-6256
Media 5.0

Cisco ASR 5000 devices with software 19.0.M0.60828 allow remote attackers to cause a denial of service (OSPF process restart) via crafted length fields in headers of OSPF packets, aka Bug ID CSCuv62820.

cisco asr_5000_series_software
0.01EPSS
CVE-2015-0776
Media 5.0

telnetd in Cisco IOS XR 5.0.1 on Network Convergence System 6000 devices allows remote attackers to cause a denial of service (device reload) via a malformed TELNET packet, aka Bug ID CSCuq31566.

cisco ios_xr
0.01EPSS
CVE-2015-0730
Media 5.0

The SMB module in Cisco Wide Area Application Services (WAAS) 6.0(1) allows remote attackers to cause a denial of service (module reload) via an invalid field in a Negotiate Protocol request, aka Bug ID CSCuo75645.

cisco wide_area_application_services
0.01EPSS
CVE-2013-1241
Media 6.3

The ISM module in Cisco IOS on ISR G2 routers does not properly handle authentication-header packets, which allows remote authenticated users to cause a denial of service (module reload) via a series of malformed packets, aka Bug ID CSCub92025.

cisco 1921_integrated_services_router · cisco 1941_integrated_services_router · cisco 1941w_integrated_services_router · cisco 2901_integrated_services_router · e altri 23
0.01EPSS
CVE-2010-1572
Alta 9.0

Unspecified vulnerability in the tech support diagnostic shell in Cisco Application Extension Platform (AXP) 1.1 and 1.1.5 allows local users to obtain sensitive configuration information and gain administrator privileges via unspecified API calls.

cisco application_extension_framework
0.01EPSS
CVE-2019-12697
Alta 7.5

Multiple vulnerabilities in the Cisco Firepower System Software Detection Engine could allow an unauthenticated, remote attacker to bypass configured Malware and File Policies for RTF and RAR file types. For more information about these vulnerabilities, see th…

cisco firepower
0.01EPSS
CVE-2019-12696
Alta 7.5

Multiple vulnerabilities in the Cisco Firepower System Software Detection Engine could allow an unauthenticated, remote attacker to bypass configured Malware and File Policies for RTF and RAR file types. For more information about these vulnerabilities, see th…

cisco firepower
0.01EPSS
CVE-2019-1951
Media 5.8

A vulnerability in the packet filtering features of Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass L3 and L4 traffic filters. The vulnerability is due to improper traffic filtering conditions on an affected device. An attacker …

cisco sd-wan_firmware
0.01EPSS
CVE-2019-1724
Alta 8.8

A vulnerability in the session management functionality of the web-based interface for Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. An at…

cisco rv320_dual_gigabit_wan_vpn_router_software · cisco rv325_dual_wan_gigabit_vpn_router_firmware
0.01EPSS