imPC@ndo EN

Vulnerabilità Cisco

6639 CVE

CVE-2018-0464
Alta 8.1

A vulnerability in Cisco Data Center Network Manager software could allow an authenticated, remote attacker to conduct directory traversal attacks and gain access to sensitive files on the targeted system. The vulnerability is due to improper validation of use…

cisco prime_data_center_network_manager
0.05EPSS
CVE-2023-20178
Alta 7.8

A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco Secure Client Software for Windows could allow a low-privileged, authenticated, local attacker to elevate privileges to those of SYSTEM. The …

cisco anyconnect_secure_mobility_client · cisco secure_client
0.05EPSS
CVE-2002-0886
Media 5.0

Cisco DSL CPE devices running CBOS 2.4.4 and earlier allows remote attackers to cause a denial of service (hang or memory consumption) via (1) a large packet to the DHCP port, (2) a large packet to the Telnet port, or (3) a flood of large packets to the CPE, w…

cisco cbos
0.05EPSS
CVE-2001-1064
Media 5.0

Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via multiple connections to the router on the (1) HTTP or (2) telnet service, which causes the router to become unresponsive and stop forwarding pa…

cisco cbos
0.05EPSS
CVE-2008-0528
Alta 10.0

Buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SIP firmware might allow remote attackers to execute arbitrary code via a SIP message with crafted MIME data.

cisco session_initiation_protocol_\(sip\)_firmware · cisco skinny_client_control_protocol_\(sccp\)_firmware
0.05EPSS
CVE-2008-0529
Alta 10.0

Buffer overflow in the telnet server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G running SCCP firmware might allow remote authenticated users to execute arbitrary code via a crafted command.

cisco session_initiation_protocol_\(sip\)_firmware · cisco skinny_client_control_protocol_\(sccp\)_firmware
0.05EPSS
CVE-2008-0530
Alta 10.0

Buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SCCP and SIP firmware might allow remote attackers to execute arbitrary code via a crafted DNS response.

cisco session_initiation_protocol_\(sip\)_firmware · cisco skinny_client_control_protocol_\(sccp\)_firmware
0.05EPSS
CVE-2006-1960
Media 5.8

Cross-site scripting (XSS) vulnerability in the appliance web user interface in Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13 allows remote attackers to inject arbitrary web script or HTML, possibly via the displayMsg parame…

cisco wireless_lan_solution_engine
0.05EPSS
CVE-2019-1917
Critica 9.1

A vulnerability in the REST API interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to bypass authentication on an affected system. The vulnerability is due to insufficient validation of HTTP requests. An attacker…

cisco vision_dynamic_signage_director
0.05EPSS
CVE-2020-3252
Media 6.5

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulne…

cisco ucs_director · cisco ucs_director_express_for_big_data
0.05EPSS
CVE-2020-3229
Alta 8.8

A vulnerability in Role Based Access Control (RBAC) functionality of Cisco IOS XE Web Management Software could allow a Read-Only authenticated, remote attacker to execute commands or configuration changes as an Admin user. The vulnerability is due to incorrec…

cisco ios_xe
0.05EPSS
CVE-2019-12643
Critica 10.0

A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass authentication on the managed Cisco IOS XE device. The vulnerability is due to an improper check performed by th…

cisco ios_xe
0.05EPSS
CVE-2017-3831
Critica 9.8

A vulnerability in the web-based GUI of Cisco Mobility Express 1800 Series Access Points could allow an unauthenticated, remote attacker to bypass authentication. The attacker could be granted full administrator privileges. The vulnerability is due to improper…

cisco aironet_access_point_software
0.05EPSS
CVE-2012-3941
Alta 9.3

Heap-based buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 before LD SP32 EP10 and T28 before T28.4 allows remote attackers to execute arbitrary code via a crafted WRF file, aka Bug ID CSCtz72850.

cisco webex_recording_format_player
0.05EPSS
CVE-2012-3940
Alta 9.3

Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 before LD SP32 EP10 and T28 before T28.4 allows remote attackers to execute arbitrary code via a crafted WRF file, aka Bug ID CSCtz72958.

cisco webex_recording_format_player
0.05EPSS
CVE-2012-3937
Alta 9.3

Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 before LD SP32 EP10 and T28 before T28.4 allows remote attackers to execute arbitrary code via a crafted WRF file, aka Bug ID CSCtz72967.

cisco webex_recording_format_player
0.05EPSS
CVE-2011-0385
Alta 10.0

The administrative web interface on Cisco TelePresence Recording Server devices with software 1.6.x and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x allows remote attackers to create or overwrite arbitrary fi…

cisco telepresence_multipoint_switch · cisco telepresence_multipoint_switch_software · cisco telepresence_recording_server · cisco telepresence_recording_server_software
0.05EPSS
CVE-2012-3938
Alta 9.3

Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 before LD SP32 EP10 and T28 before T28.4 allows remote attackers to execute arbitrary code via a crafted WRF file, aka Bug ID CSCtz73583.

cisco webex_recording_format_player
0.05EPSS
CVE-2012-3936
Alta 9.3

Buffer overflow in the Cisco WebEx Recording Format (WRF) player T27 before LD SP32 EP10 and T28 before T28.4 allows remote attackers to execute arbitrary code via a crafted WRF file, aka Bug ID CSCua40962.

cisco webex_recording_format_player
0.05EPSS
CVE-2017-3851
Alta 7.5

A Directory Traversal vulnerability in the web framework code of the Cisco application-hosting framework (CAF) component of the Cisco IOx application environment could allow an unauthenticated, remote attacker to read any file from the CAF in the virtual insta…

cisco iox
0.05EPSS
CVE-2010-0581
Alta 10.0

Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message, aka Bug ID CSCsz89904, the "SIP Packet Parsing Arbitrary Code Execution Vulnerability."

cisco ios
0.05EPSS
CVE-2010-0580
Alta 10.0

Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message, aka Bug ID CSCsz48680, the "SIP Message Processing Arbitrary Code Execution Vulnerability."

cisco ios
0.05EPSS
CVE-2018-0268
Critica 10.0

A vulnerability in the container management subsystem of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and gain elevated privileges. This vulnerability is due to an insecure default con…

cisco digital_network_architecture_center
0.05EPSS
CVE-2005-3669
Media 5.0

Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a denial of service (device reset) via certain malformed IKE packets, as demonstrated by the PROTOS IS…

cisco adaptive_security_appliance_software · cisco firewall_services_module · cisco ios · cisco mds_9000 · e altri 4
0.05EPSS
CVE-2018-0238
Critica 9.9

A vulnerability in the role-based resource checking functionality of the Cisco Unified Computing System (UCS) Director could allow an authenticated, remote attacker to view unauthorized information for any virtual machine in the UCS Director end-user portal an…

cisco unified_computing_system_director
0.05EPSS