imPC@ndo EN

Vulnerabilità Cisco

6642 CVE

CVE-2015-0715
Media 6.5

SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug IDs CSCut33447 and CSCut33608.

cisco unity_connection
0.01EPSS
CVE-2013-1143
Alta 7.1

The RSVP protocol implementation in Cisco IOS 12.2 and 15.0 through 15.2 and IOS XE 3.1.xS through 3.4.xS before 3.4.5S and 3.5.xS through 3.7.xS before 3.7.2S, when MPLS-TE is enabled, allows remote attackers to cause a denial of service (incorrect memory acc…

cisco ios · cisco ios_xe
0.01EPSS
CVE-2015-6387
Media 4.3

Cross-site scripting (XSS) vulnerability in Cisco Unified Computing System (UCS) Central Software 1.3(0.1) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCux33573.

cisco unified_computing_system_central_software
0.01EPSS
CVE-2015-6390
Media 4.3

Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unity Connection 9.1(1.10) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCup92741.

cisco unity_connection
0.01EPSS
CVE-2015-6349
Media 4.3

Cross-site scripting (XSS) vulnerability in the web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

cisco secure_access_control_server
0.01EPSS
CVE-2015-6346
Media 4.3

Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

cisco secure_access_control_server
0.01EPSS
CVE-2015-6268
Alta 7.8

Cisco IOS XE before 2.2.3 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted IPv4 UDP packet, aka Bug ID CSCsw95482.

cisco ios_xe
0.01EPSS
CVE-2015-4294
Media 4.3

Cross-site scripting (XSS) vulnerability in Cisco IM and Presence Service before 10.5 MR1 allows remote attackers to inject arbitrary web script or HTML by constructing a crafted URL that leverages incomplete filtering of HTML elements, aka Bug ID CSCut41766.

cisco unified_communications_manager_im_and_presence_service
0.01EPSS
CVE-2015-4292
Media 4.3

Cross-site scripting (XSS) vulnerability in the management interface in Cisco Prime Central for Hosted Collaboration Solution (PC4HCS) 10.6(2) allows remote attackers to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCuv45818.

cisco prime_central_for_hosted_collaboration_solution_assurance
0.01EPSS
CVE-2015-4283
Alta 7.8

Cisco Videoscape Policy Resource Manager (PRM) 3.5.4 allows remote attackers to cause a denial of service (CPU and memory consumption, and TCP service outage) via (1) a SYN flood or (2) another type of TCP traffic flood, aka Bug IDs CSCuu35104 and CSCuu35128.

cisco videoscape_policy_resource_manager
0.01EPSS
CVE-2015-0714
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Finesse Server 10.0(1), 10.5(1), 10.6(1), and 11.0(1) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCut53595.

cisco finesse
0.01EPSS
CVE-1999-0843
Media 5.0

Denial of service in Cisco routers running NAT via a PORT command from an FTP client to a Telnet port.

cisco router
0.01EPSS
CVE-2014-3396
Alta 7.5

Cisco IOS XR on ASR 9000 devices does not properly use compression for port-range and address-range encoding, which allows remote attackers to bypass intended Typhoon line-card ACL restrictions via transit traffic, aka Bug ID CSCup30133.

cisco asr_9000_rsp440_router · cisco asr_9001 · cisco asr_9006 · cisco asr_9010 · e altri 4
0.01EPSS
CVE-1999-0222
Media 5.0

Denial of service in Cisco IOS web server allows attackers to reboot the router using a long URL.

cisco router
0.01EPSS
CVE-2024-20287
Media 6.5

A vulnerability in the web-based management interface of the Cisco WAP371 Wireless-AC/N Dual Radio Access Point (AP) with Single Point Setup could allow an authenticated, remote attacker to perform command injection attacks against an affected device. This vul…

cisco wap371_firmware
0.01EPSS
CVE-2019-1678
Media 4.3

A vulnerability in Cisco Meeting Server could allow an authenticated, remote attacker to cause a partial denial of service (DoS) to Cisco Meetings application users who are paired with a Session Initiation Protocol (SIP) endpoint. The vulnerability is due to i…

cisco meeting_server
0.01EPSS
CVE-2021-1590
Media 5.3

A vulnerability in the implementation of the system login block-for command for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a login process to unexpectedly restart, causing a denial of service (DoS) condition. This vulnerabili…

cisco nx-os · cisco unified_computing_system
0.01EPSS
CVE-2018-0225
Critica 9.8

The Enterprise Console in Cisco AppDynamics App iQ Platform before 4.4.3.10598 (HF4) allows SQL injection, aka the Security Advisory 2089 issue.

cisco appdynamics_app_iq
0.01EPSS
CVE-2016-1459
Media 5.3

Cisco IOS 12.4 and 15.0 through 15.5 and IOS XE 3.13 through 3.17 allow remote authenticated users to cause a denial of service (device reload) via crafted attributes in a BGP message, aka Bug ID CSCuz21061.

cisco ios · cisco ios_xe
0.01EPSS
CVE-2009-1164
Alta 7.8

The administrative web interface on the Cisco Wireless LAN Controller (WLC) platform 4.2 before 4.2.205.0 and 5.x before 5.2.178.0, as used in Cisco 1500 Series, 2000 Series, 2100 Series, 4100 Series, 4200 Series, and 4400 Series Wireless Services Modules (WiS…

cisco catalyst_3750g · cisco cisco_1500_wireless_lan_controller · cisco cisco_2000_wireless_lan_controller · cisco cisco_2100_wireless_lan_controller · e altri 3
0.01EPSS
CVE-2015-0583
Media 5.0

Cisco WebEx Meeting Center does not properly restrict the content of URLs, which allows remote attackers to obtain sensitive information via vectors related to file: URIs, aka Bug ID CSCus18281.

cisco webex_meeting_center
0.01EPSS
CVE-2014-8035
Media 5.0

The web framework in Cisco WebEx Meetings Server produces different returned messages for URL requests depending on whether a username exists, which allows remote attackers to enumerate user accounts via a series of requests, aka Bug ID CSCuj40247.

cisco webex_meetings_server
0.01EPSS
CVE-2014-3281
Media 5.0

The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) does not properly implement access control, which allows remote attackers to obtain potentially sensitive user information by visiting an unspecified BVSMWeb web page, aka Bug IDs C…

cisco unified_communications_domain_manager
0.01EPSS
CVE-2014-3278
Media 5.0

The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) does not properly implement access control, which allows remote attackers to enumerate accounts by visiting an unspecified BVSMWeb web page, aka Bug IDs CSCun39619 and CSCun45572.

cisco unified_communications_domain_manager
0.01EPSS
CVE-2013-5502
Media 5.0

The web interface in Cisco MediaSense does not properly protect the client-server communication channel, which allows remote attackers to obtain sensitive query string or cookie information via unspecified vectors, aka Bug ID CSCuj23344.

cisco mediasense
0.01EPSS