imPC@ndo EN

Vulnerabilità Cisco

6639 CVE

CVE-2013-3383
Alta 9.0

The web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-550 allows remote authenticated users to execute arbitrary commands via crafted command-line input in a URL sent over IPv…

cisco ironport_asyncos
0.03EPSS
CVE-2018-0345
Alta 8.8

A vulnerability in the configuration and management database of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to execute arbitrary commands with the privileges of the vmanage user in the configuration management system of the affected…

cisco vbond_orchestrator · cisco vedge-1000_firmware · cisco vedge-100_firmware · cisco vedge-2000_firmware · e altri 8
0.03EPSS
CVE-2007-2688
Alta 7.8

The Cisco Intrusion Prevention System (IPS) and IOS with Firewall/IPS Feature Set do not properly handle certain full-width and half-width Unicode character encodings, which might allow remote attackers to evade detection of HTTP traffic.

cisco ios · cisco ips_sensor_software
0.03EPSS
CVE-2015-0582
Media 5.0

The High Availability (HA) subsystem in Cisco NX-OS on MDS 9000 devices allows remote attackers to cause a denial of service via crafted traffic, aka Bug ID CSCuo09129.

cisco nx-os
0.03EPSS
CVE-2012-4091
Media 5.0

The RIP service engine in Cisco NX-OS allows remote attackers to cause a denial of service (engine restart) via a malformed (1) RIPv4 or (2) RIPv6 message, aka Bug ID CSCtj73415.

cisco nx-os
0.03EPSS
CVE-2016-1479
Alta 7.5

Cisco IP Phone 8800 devices with software 11.0(1) allow remote attackers to cause a denial of service (memory corruption) via a crafted HTTP request, aka Bug ID CSCuz03038.

cisco ip_phone_8800_series_firmware
0.03EPSS
CVE-2010-0583
Alta 7.8

Memory leak in the H.323 implementation in Cisco IOS 12.1 through 12.4, and 15.0M before 15.0(1)M1, allows remote attackers to cause a denial of service (memory consumption and device reload) via malformed H.323 packets, aka Bug ID CSCtb93855.

cisco ios
0.03EPSS
CVE-2006-3734
Alta 7.2

Multiple unspecified vulnerabilities in the Command Line Interface (CLI) for Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1, allow local CS-MARS administrators to execute arbitrary commands as root.

cisco cs-mars
0.03EPSS
CVE-2016-6356
Alta 7.5

A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances could allow an unauthenticated, remote attacker to cause an affected device to stop scanning and forwarding email messages due to a denial of s…

cisco email_security_appliance
0.03EPSS
CVE-2016-1486
Alta 7.5

A vulnerability in the email attachment scanning functionality of the Advanced Malware Protection (AMP) feature of Cisco AsyncOS Software for Cisco Email Security Appliances could allow an unauthenticated, remote attacker to cause an affected device to stop sc…

cisco email_security_appliance
0.03EPSS
CVE-2013-3470
Media 5.0

The RIP process in Cisco IOS XR allows remote attackers to cause a denial of service (process crash) via a crafted version-2 RIP packet, aka Bug ID CSCue46731.

cisco ios_xr
0.03EPSS
CVE-2019-15260
Critica 9.8

A vulnerability in Cisco Aironet Access Points (APs) Software could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device with elevated privileges. The vulnerability is due to insufficient access control for certain URLs on…

cisco aironet_1540_firmware · cisco aironet_1560_firmware · cisco aironet_1800_firmware · cisco aironet_2800_firmware · e altri 2
0.03EPSS
CVE-2017-6704
Media 6.5

A vulnerability in the web application in the Cisco Prime Collaboration Provisioning tool could allow an authenticated, remote attacker to perform arbitrary file downloads that could allow the attacker to read files from the underlying filesystem. More Informa…

cisco prime_collaboration_provisioning
0.03EPSS
CVE-2013-2139
Bassa 2.6

Buffer overflow in srtp.c in libsrtp in srtp 1.4.5 and earlier allows remote attackers to cause a denial of service (crash) via vectors related to a length inconsistency in the crypto_policy_set_from_profile_for_rtp and srtp_protect functions.

cisco libsrtp · fedoraproject fedora · opensuse opensuse
0.03EPSS
CVE-2017-3825
Alta 7.5

A vulnerability in the ICMP ingress packet processing of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an unauthenticated, remote attacker to cause the TelePresence endpoint to reload unexpectedly, resulting in a denial of service (DoS) c…

cisco telepresence_ce · cisco telepresence_tc
0.03EPSS
CVE-2015-0775
Media 5.0

The banner (aka MOTD) implementation in Cisco NX-OS 4.1(2)E1(1f) on Nexus 4000 devices, 5.2(1)SV3(2.1) on Nexus 1000V devices, 6.0(2)N2(2) on Nexus 5000 devices, 6.2(11) on MDS 9000 devices, 6.2(12) on Nexus 7000 devices, 7.0(3) on Nexus 9000 devices, and 7.2(…

cisco mds_9000_nx-os · cisco nexus_1000v · cisco nx-os
0.03EPSS
CVE-2015-0742
Media 5.0

The Protocol Independent Multicast (PIM) application in Cisco Adaptive Security Appliance (ASA) Software 9.2(0.0), 9.2(0.104), 9.2(3.1), 9.2(3.4), 9.3(1.105), 9.3(2.100), 9.4(0.115), 100.13(0.21), 100.13(20.3), 100.13(21.9), and 100.14(1.1) does not properly i…

cisco adaptive_security_appliance_software
0.03EPSS
CVE-2014-3318
Media 4.0

Directory traversal vulnerability in dna/viewfilecontents.do in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager allows remote authenticated users to read arbitrary files via a crafted URL, aka Bug ID CSCup76318.

cisco unified_communications_manager
0.03EPSS
CVE-2017-12372
Critica 9.6

A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user wit…

cisco webex_meetings · cisco webex_meetings_server
0.03EPSS
CVE-2017-12371
Critica 9.6

A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user wit…

cisco webex_meetings
0.03EPSS
CVE-2017-12370
Critica 9.6

A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user wit…

cisco webex_meetings
0.03EPSS
CVE-2017-12369
Critica 9.6

A "Cisco WebEx Network Recording Player Out-of-Bounds Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user with a mali…

cisco webex_meetings
0.03EPSS
CVE-2017-12368
Critica 9.6

A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user wit…

cisco webex_meetings · cisco webex_meetings_server
0.03EPSS
CVE-2015-6314
Critica 9.8

Cisco Wireless LAN Controller (WLC) devices with software 7.6.x, 8.0 before 8.0.121.0, and 8.1 before 8.1.131.0 allow remote attackers to change configuration settings via unspecified vectors, aka Bug ID CSCuw06153.

cisco wireless_lan_controller_software
0.03EPSS
CVE-2021-1318
Alta 7.2

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. Thes…

cisco rv016_multi-wan_vpn_router_firmware · cisco rv042_dual_wan_vpn_router_firmware · cisco rv042g_dual_gigabit_wan_vpn_router_firmware · cisco rv082_dual_wan_vpn_router_firmware · e altri 2
0.03EPSS