imPC@ndo EN

Vulnerabilità Cisco

6639 CVE

CVE-2026-20186
Critica 9.9

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read On…

cisco identity_services_engine
0.06EPSS
CVE-2019-1681
Alta 7.5

A vulnerability in the TFTP service of Cisco Network Convergence System 1000 Series software could allow an unauthenticated, remote attacker to retrieve arbitrary files from the targeted device, possibly resulting in information disclosure. The vulnerability i…

cisco ios_xr
0.06EPSS
CVE-2008-4391
Alta 9.3

Stack-based buffer overflow in the SetSource method in the NetCamPlayerWeb11gv2 ActiveX control in NetCamPlayerWeb11gv2.ocx on the Cisco Linksys WVC54GC wireless video camera before firmware 1.25 allows remote attackers to execute arbitrary code via long inval…

cisco wvc54gc
0.06EPSS
CVE-2017-6621
Alta 7.5

A vulnerability in the web interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to access sensitive data. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is …

cisco prime_collaboration_provisioning
0.06EPSS
CVE-2016-1289
Critica 9.8

The API in Cisco Prime Infrastructure 1.2 through 3.0 and Evolved Programmable Network Manager (EPNM) 1.2 allows remote attackers to execute arbitrary code or obtain sensitive management information via a crafted HTTP request, as demonstrated by discovering ma…

cisco evolved_programmable_network_manager · cisco prime_infrastructure
0.06EPSS
CVE-2018-0427
Alta 8.8

A vulnerability in the CronJob scheduler API of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to perform a command injection attack. The vulnerability is due to incorrect input validation of user-supplied data. A…

cisco application_policy_infrastructure_controller_enterprise_module
0.06EPSS
CVE-2002-1360
Alta 10.0

Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to inter…

cisco ios · fissh ssh_client · intersoft securenetterm · netcomposite shellguard_ssh · e altri 3
0.06EPSS
CVE-2012-0358
Alta 9.3

Buffer overflow in the Cisco Port Forwarder ActiveX control in cscopf.ocx, as distributed through the Clientless VPN feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.0 through 7.2 before 7.2(5.6), 8.0 before 8.0(5.26), 8.…

cisco 5500_series_adaptive_security_appliance · cisco adaptive_security_appliance_software
0.06EPSS
CVE-2022-20968
Alta 8.1

A vulnerability in the Cisco Discovery Protocol processing feature of Cisco IP Phone 7800 and 8800 Series firmware could allow an unauthenticated, adjacent attacker to cause a stack overflow on an affected device. This vulnerability is due to insufficient i…

cisco ip_phone_7811_firmware · cisco ip_phone_7821_firmware · cisco ip_phone_7832_firmware · cisco ip_phone_7841_firmware · e altri 9
0.06EPSS
CVE-2003-0210
Alta 7.5

Buffer overflow in the administration service (CSAdmin) for Cisco Secure ACS before 3.1.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long user parameter to port 2002.

cisco secure_access_control_server
0.06EPSS
CVE-2013-3443
Alta 10.0

The web service framework in Cisco WAAS Software 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1 in a Central Manager (CM) configuration allows remote attackers to execute arbitrary code via a crafted POST request, aka Bug ID CSCuh26626.…

cisco wide_area_application_services
0.06EPSS
CVE-2010-3036
Alta 10.0

Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary code via a session on TCP port (1) 443 or (2) 1741, aka Bug ID CSCti41352.

cisco ciscoworks_common_services · cisco ciscoworks_lan_management_solution · cisco qos_policy_manager · cisco security_manager · e altri 3
0.06EPSS
CVE-2007-5583
Alta 7.8

Cisco IP Phone 7940 with firmware P0S3-08-7-00 allows remote attackers to cause a denial of service ("486 Busy" responses or device reboot) via a sequence of SIP INVITE transactions in which the Request-URI lacks a user name, a different vulnerability than CVE…

cisco ip_phone_7940
0.06EPSS
CVE-2018-0314
Critica 9.8

A vulnerability in the Cisco Fabric Services (CFS) component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability exists because the affected software…

cisco firepower_9000_firmware · cisco nexus_5000_firmware · cisco nexus_7000_firmware · cisco nexus_9000_firmware · e altri 1
0.06EPSS
CVE-2017-6753
Alta 8.8

A vulnerability in Cisco WebEx browser extensions for Google Chrome and Mozilla Firefox could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the affected browser on an affected system. This vulnerability affects the …

cisco webex_event_center · cisco webex_meeting_center · cisco webex_meetings · cisco webex_meetings_server · e altri 16
0.06EPSS
CVE-2011-0384
Alta 10.0

The Java Servlet framework on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x does not require administrative authentication for unspecified actions, which allows remote attackers to execute arbitrary code via a…

cisco telepresence_multipoint_switch · cisco telepresence_multipoint_switch_software
0.06EPSS
CVE-2014-0648
Alta 10.0

The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authentication and authorization requirements, which allows remote attackers to obtain administrative access via a request to this interface, aka Bug ID CSCu…

cisco secure_access_control_system
0.06EPSS
CVE-2003-0647
Alta 7.5

Buffer overflow in the HTTP server for Cisco IOS 12.2 and earlier allows remote attackers to execute arbitrary code via an extremely long (2GB) HTTP GET request.

cisco ios
0.06EPSS
CVE-2017-6636
Media 6.5

A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11.1) could allow an authenticated, remote attacker to view any file on an affected system. The vulnerability exists because the affected software does no…

cisco prime_collaboration_provisioning
0.06EPSS
CVE-2018-0341
Alta 8.8

A vulnerability in the web-based UI of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware before 11.2(1) could allow an authenticated, remote attacker to perform a command injection and execute commands with the privileges of the web server…

cisco ip_phone_multiplatform_firmware
0.06EPSS
CVE-2002-2379
Alta 7.8

Cisco AS5350 IOS 12.2(11)T with access control lists (ACLs) applied and possibly with ssh running allows remote attackers to cause a denial of service (crash) via a port scan, possibly due to an ssh bug. NOTE: this issue could not be reproduced by the vendor

cisco as5350
0.06EPSS
CVE-2017-6683
Alta 8.8

A vulnerability in the esc_listener.py script of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to execute arbitrary commands as the tomcat user on an affected system, aka an Authentication Request Processing Arbitrary Command…

cisco elastic_services_controller
0.06EPSS
CVE-2002-1358
Alta 10.0

Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.

cisco ios · fissh ssh_client · intersoft securenetterm · netcomposite shellguard_ssh · e altri 3
0.06EPSS
CVE-2019-1723
Critica 9.8

A vulnerability in the Cisco Common Services Platform Collector (CSPC) could allow an unauthenticated, remote attacker to access an affected device by using an account that has a default, static password. This account does not have administrator privileges. Th…

cisco common_services_platform_collector
0.06EPSS
CVE-2022-20771
Alta 7.5

On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in the TIFF file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS versio…

cisco secure_endpoint · clamav clamav · debian debian_linux · fedoraproject fedora
0.06EPSS