VYPR

Cisco iOS

by Cisco Systems, Inc.

CVEs (652)

  • CVE-2001-0537Jul 21, 2001
    risk 0.08cvss —epss 0.68

    HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL.

  • CVE-2000-0380Apr 26, 2000
    risk 0.06cvss —epss 0.35

    The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a URL that contains a %% string.

  • CVE-2014-7992Nov 18, 2014
    risk 0.05cvss —epss 0.27

    The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensitive credential information from process memory via a session on TCP port 2067, aka Bug ID CSCur14014.

  • CVE-2007-4286Aug 9, 2007
    risk 0.05cvss —epss 0.19

    Buffer overflow in the Next Hop Resolution Protocol (NHRP) functionality in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (restart) and execute arbitrary code via a crafted NHRP packet.

  • CVE-2009-1220Apr 1, 2009
    risk 0.04cvss —epss 0.09

    Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA) 5520 with software 7.2(4)30 and earlier 7.2 versions including 7.2(2)22, and 8.0(4)28 and earlier 8.0 versions, when clientless mode is enabled, allows…

  • CVE-2007-5381Oct 12, 2007
    risk 0.04cvss —epss 0.15

    Stack-based buffer overflow in the Line Printer Daemon (LPD) in Cisco IOS before 12.2(18)SXF11, 12.4(16a), and 12.4(2)T6 allow remote attackers to execute arbitrary code by setting a long hostname on the target system, then causing an error message to be printed, as demonstrated…

  • CVE-2007-4430Aug 20, 2007
    risk 0.04cvss —epss 0.13

    Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routing table rebuild) via certain regular expressions in a "show ip bgp regexp" command. NOTE: unauthenticated remote attacks are…

  • CVE-2007-2586May 10, 2007
    risk 0.04cvss —epss 0.14

    The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated by a crafted MKD command that involves access to a VTY…

  • CVE-2006-0354Jan 22, 2006
    risk 0.04cvss —epss 0.10

    Cisco IOS before 12.3-7-JA2 on Aironet Wireless Access Points (WAP) allows remote authenticated users to cause a denial of service (termination of packet passing or termination of client connections) by sending the management interface a large number of spoofed ARP packets,…

  • CVE-2005-2841Sep 8, 2005
    risk 0.04cvss —epss 0.14

    Buffer overflow in Firewall Authentication Proxy for FTP and/or Telnet Sessions for Cisco IOS 12.2ZH and 12.2ZL, 12.3 and 12.3T, and 12.4 and 12.4T allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted user authentication…

  • CVE-2003-0511Aug 27, 2003
    risk 0.04cvss —epss 0.09

    The web server for Cisco Aironet AP1x00 Series Wireless devices running certain versions of IOS 12.2 allow remote attackers to cause a denial of service (reload) via a malformed URL.

  • CVE-2003-0567Aug 18, 2003
    risk 0.04cvss —epss 0.17

    Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 packets to an interface on the device, causing the input queue on that interface to be marked as full.

  • CVE-2003-0100Mar 3, 2003
    risk 0.04cvss —epss 0.10

    Buffer overflow in Cisco IOS 11.2.x to 12.0.x allows remote attackers to cause a denial of service and possibly execute commands via a large number of OSPF neighbor announcements.

  • CVE-2002-2315Dec 31, 2002
    risk 0.04cvss —epss 0.10

    Cisco IOS 11.2.x and 12.0.x does not limit the size of its redirect table, which allows remote attackers to cause a denial of service (memory consumption) via spoofed ICMP redirect packets to the router.

  • CVE-2002-0813Aug 12, 2002
    risk 0.04cvss —epss 0.09

    Heap-based buffer overflow in the TFTP server capability in Cisco IOS 11.1, 11.2, and 11.3 allows remote attackers to cause a denial of service (reset) or modify configuration via a long filename.

  • CVE-1999-0063Jan 11, 1999
    risk 0.04cvss —epss 0.08

    Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port.

  • CVE-2009-0470Feb 6, 2009
    risk 0.03cvss —epss 0.04

    Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 12.4(23) allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) level/15/exec/-/ or (2) exec/, a different vulnerability than CVE-2008-3821.

  • CVE-2008-3821Jan 16, 2009
    risk 0.03cvss —epss 0.05

    Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 11.0 through 12.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the ping program or (2) unspecified other aspects of the URI.

  • CVE-2008-4609Oct 20, 2008
    risk 0.03cvss —epss 0.32

    The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate…

  • CVE-2004-0244Nov 23, 2004
    risk 0.03cvss —epss 0.01

    Cisco 6000, 6500, and 7600 series systems with Multilayer Switch Feature Card 2 (MSFC2) and a FlexWAN or OSM module allow local users to cause a denial of service (hang or reset) by sending a layer 2 frame packet that encapsulates a layer 3 packet, but has inconsistent length…

Page 13 of 33