imPC@ndo EN

Vulnerabilità Cisco

6639 CVE

CVE-2019-15993
Media 5.3

A vulnerability in the web UI of Cisco Small Business Switches could allow an unauthenticated, remote attacker to access sensitive device information. The vulnerability exists because the software lacks proper authentication controls to information accessible …

cisco sf200-24_firmware · cisco sf200-24fp_firmware · cisco sf200-24p_firmware · cisco sf200-48_firmware · e altri 110
0.10EPSS
CVE-2013-1114
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unity Express before 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCud87527.

cisco unity_express_software
0.10EPSS
CVE-2004-1099
Alta 10.0

Cisco Secure Access Control Server for Windows (ACS Windows) and Cisco Secure Access Control Server Solution Engine (ACS Solution Engine) 3.3.1, when the EAP-TLS protocol is enabled, does not properly handle expired or untrusted certificates, which allows remo…

cisco secure_access_control_server · cisco secure_acs_solution_engine
0.10EPSS
CVE-2013-3429
Alta 7.8

Multiple directory traversal vulnerabilities in Cisco Video Surveillance Manager (VSM) before 7.0.0 allow remote attackers to read system files via a crafted URL, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv37163.

cisco video_surveillance_manager
0.10EPSS
CVE-2013-2681
Critica 9.8

Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access.

cisco linksys_e4200_firmware
0.10EPSS
CVE-2019-1717
Alta 7.5

A vulnerability in the web-based management interface of Cisco Video Surveillance Manager could allow an unauthenticated, remote attacker to access sensitive information. The vulnerability is due to improper validation of parameters handled by the web-based ma…

cisco video_surveillance_manager
0.10EPSS
CVE-2016-1464
Alta 7.8

Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to execute arbitrary code via a crafted file, aka Bug ID CSCva09375.

cisco webex_wrf_player_t29
0.10EPSS
CVE-2006-0515
Alta 7.5

Cisco PIX/ASA 7.1.x before 7.1(2) and 7.0.x before 7.0(5), PIX 6.3.x before 6.3.5(112), and FWSM 2.3.x before 2.3(4) and 3.x before 3.1(7), when used with Websense/N2H2, allows remote attackers to bypass HTTP access restrictions by splitting the GET method of …

cisco adaptive_security_appliance_software · cisco firewall_services_module · cisco pix_firewall · cisco pix_firewall_software
0.10EPSS
CVE-2002-1357
Alta 10.0

Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol …

cisco ios · fissh ssh_client · intersoft securenetterm · netcomposite shellguard_ssh · e altri 3
0.10EPSS
CVE-2017-6635
Media 6.5

A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 12.1) could allow an authenticated, remote attacker to delete any file from an affected system. The vulnerability exists because the affected software doe…

cisco prime_collaboration_provisioning
0.10EPSS
CVE-2021-1571
Alta 7.2

Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Con…

cisco sf220-24_firmware · cisco sf220-24p_firmware · cisco sf220-48_firmware · cisco sf220-48p_firmware · e altri 5
0.10EPSS
CVE-2021-1609
Critica 9.8

Multiple vulnerabilities in the web-based management interface of the Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an attacker to do the following: Execute arbitrary code Cause a denial of service (DoS) conditi…

cisco small_business_rv_series_router_firmware
0.10EPSS
CVE-2003-0100
Alta 7.5

Buffer overflow in Cisco IOS 11.2.x to 12.0.x allows remote attackers to cause a denial of service and possibly execute commands via a large number of OSPF neighbor announcements.

cisco ios
0.10EPSS
CVE-2006-5277
Alta 9.3

Off-by-one error in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM, formerly CallManager) before 20070711 allow remote attackers to execute arbitrary code via a crafted packet that triggers a h…

cisco unified_callmanager · cisco unified_communications_manager
0.10EPSS
CVE-2002-2315
Alta 7.8

Cisco IOS 11.2.x and 12.0.x does not limit the size of its redirect table, which allows remote attackers to cause a denial of service (memory consumption) via spoofed ICMP redirect packets to the router.

cisco ios
0.10EPSS
CVE-2004-0079
Alta 7.5

The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.

4d webstar · apple mac_os_x · apple mac_os_x_server · avaya converged_communications_server · e altri 62
0.10EPSS
CVE-2019-1978
Media 5.8

A vulnerability in the stream reassembly component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker to bypass filtering protect…

cisco firepower_services_software_for_asa · cisco secure_firewall_management_center · cisco secure_firewall_threat_defense
0.09EPSS
CVE-2021-1543
Alta 7.2

Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Con…

cisco sf220-24_firmware · cisco sf220-24p_firmware · cisco sf220-48_firmware · cisco sf220-48p_firmware · e altri 5
0.09EPSS
CVE-2016-1336
Alta 7.5

goform/Docsis_system on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a long LanguageSelect parameter, related to a "Gateway HTTP Corruption Denial of Service" issue, aka Bug ID CSCuy28100.

cisco epc3928_firmware
0.09EPSS
CVE-2016-1328
Alta 7.5

goform/WClientMACList on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a long h_sortWireless parameter, related to a "Gateway Client List Denial of Service" issue, aka Bug ID CSCux24948.

cisco epc3928_firmware
0.09EPSS
CVE-2013-3431
Alta 7.8

Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages, which allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco…

cisco video_surveillance_manager
0.09EPSS
CVE-2007-0480
Alta 10.0

Cisco IOS 9.x, 10.x, 11.x, and 12.x and IOS XR 2.0.x, 3.0.x, and 3.2.x allows remote attackers to cause a denial of service or execute arbitrary code via a crafted IP option in the IP header in a (1) ICMP, (2) PIMv2, (3) PGM, or (4) URD packet.

cisco ios_transmission_control_protocol
0.09EPSS
CVE-2007-1542
Media 5.0

Unspecified vulnerability in the Cisco IP Phone 7940 and 7960 running firmware before POS8-6-0 allows remote attackers to cause a denial of service via the Remote-Party-ID sipURI field in a SIP INVITE request. NOTE: the provenance of this information is unknow…

cisco 7940_router · cisco 7960_router
0.09EPSS
CVE-2000-0613
Media 5.0

Cisco Secure PIX Firewall does not properly identify forged TCP Reset (RST) packets, which allows remote attackers to force the firewall to close legitimate connections.

cisco pix_firewall
0.09EPSS
CVE-2002-0813
Alta 7.1

Heap-based buffer overflow in the TFTP server capability in Cisco IOS 11.1, 11.2, and 11.3 allows remote attackers to cause a denial of service (reset) or modify configuration via a long filename.

cisco ios
0.09EPSS