VYPR

Vendor CVEs

Cisco Systems, Inc.

All CVEs

7,058 total · sorted by risk
  • CVE-2007-0967Feb 16, 2007
    risk 0.00cvss —epss 0.02

    Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.1) allows remote attackers to cause a denial of service (device reboot) via malformed SNMP requests.

  • CVE-2007-0961Feb 16, 2007
    risk 0.00cvss —epss 0.03

    Cisco PIX 500 and ASA 5500 Series Security Appliances 6.x before 6.3(5.115), 7.0 before 7.0(5.2), and 7.1 before 7.1(2.5), and the FWSM 3.x before 3.1(3.24), when the "inspect sip" option is enabled, allows remote attackers to cause a denial of service (device reboot) via…

  • CVE-2007-0965Feb 16, 2007
    risk 0.00cvss —epss 0.02

    Cisco FWSM 3.x before 3.1(3.2), when authentication is configured to use "aaa authentication match" or "aaa authentication include", allows remote attackers to cause a denial of service (device reboot) via a long HTTP request.

  • CVE-2007-0962Feb 16, 2007
    risk 0.00cvss —epss 0.02

    Cisco PIX 500 and ASA 5500 Series Security Appliances 7.0 before 7.0(4.14) and 7.1 before 7.1(2.1), and the FWSM 2.x before 2.3(4.12) and 3.x before 3.1(3.24), when "inspect http" is enabled, allows remote attackers to cause a denial of service (device reboot) via malformed HTTP…

  • CVE-2007-0959Feb 16, 2007
    risk 0.00cvss —epss 0.02

    Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to inspect certain TCP-based protocols, allows remote attackers to cause a denial of service (device reboot) via malformed TCP packets.

  • CVE-2007-0968Feb 16, 2007
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in Cisco Firewall Services Module (FWSM) before 2.3(4.7) and 3.x before 3.1(3.1) causes the access control entries (ACE) in an ACL to be improperly evaluated, which allows remote authenticated users to bypass intended certain ACL protections.

  • CVE-2007-0966Feb 16, 2007
    risk 0.00cvss —epss 0.02

    Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.11), when the HTTPS server is enabled, allows remote attackers to cause a denial of service (device reboot) via certain HTTPS traffic.

  • CVE-2007-0960Feb 16, 2007
    risk 0.00cvss —epss 0.03

    Unspecified vulnerability in Cisco PIX 500 and ASA 5500 Series Security Appliances 7.2.2, when configured to use the LOCAL authentication method, allows remote authenticated users to gain privileges via unspecified vectors.

  • CVE-2007-0917Feb 14, 2007
    risk 0.00cvss —epss 0.02

    The Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XE to 12.3T allows remote attackers to bypass IPS signatures that use regular expressions via fragmented packets.

  • CVE-2007-0918Feb 14, 2007
    risk 0.00cvss —epss 0.03

    The ATOMIC.TCP signature engine in the Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XA, 12.3YA, 12.3T, and other trains allows remote attackers to cause a denial of service (IPS crash and traffic loss) via unspecified manipulations that are not properly handled by…

  • CVE-2007-0648Feb 1, 2007
    risk 0.00cvss —epss 0.04

    Cisco IOS after 12.3(14)T, 12.3(8)YC1, 12.3(8)YG, and 12.4, with voice support and without Session Initiated Protocol (SIP) configured, allows remote attackers to cause a denial of service (crash) by sending a crafted packet to port 5060/UDP.

  • CVE-2007-0479Jan 25, 2007
    risk 0.00cvss —epss 0.04

    Memory leak in the TCP listener in Cisco IOS 9.x, 10.x, 11.x, and 12.x allows remote attackers to cause a denial of service by sending crafted TCP traffic to an IPv4 address on the IOS device.

  • CVE-2007-0481Jan 25, 2007
    risk 0.00cvss —epss 0.05

    Cisco IOS allows remote attackers to cause a denial of service (crash) via a crafted IPv6 Type 0 Routing header.

  • CVE-2007-0397Jan 20, 2007
    risk 0.00cvss —epss 0.03

    The Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.3 and Adaptive Security Device Manager (ASDM) before 5.2(2.54) do not validate the SSL/TLS certificates or SSH public keys when connecting to devices, which allows remote attackers to spoof those…

  • CVE-2007-0198Jan 11, 2007
    risk 0.00cvss —epss 0.02

    The JTapi Gateway process in Cisco Unified Contact Center Enterprise, Unified Contact Center Hosted, IP Contact Center Enterprise, and Cisco IP Contact Center Hosted 5.0 through 7.1 allows remote attackers to cause a denial of service (repeated process restart) via a certain TCP…

  • CVE-2007-0199Jan 11, 2007
    risk 0.00cvss —epss 0.03

    The Data-link Switching (DLSw) feature in Cisco IOS 11.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via "an invalid value in a DLSw message... during the capabilities exchange."

  • CVE-2007-0057Jan 4, 2007
    risk 0.00cvss —epss 0.04

    Cisco Clean Access (CCA) 3.6.x through 3.6.4.2 and 4.0.x through 4.0.3.2 does not properly configure or allow modification of a shared secret authentication key, which causes all devices to have the same shared sercet and allows remote attackers to gain unauthorized access.

  • CVE-2007-0058Jan 4, 2007
    risk 0.00cvss —epss 0.03

    Cisco Clean Access (CCA) 3.5.x through 3.5.9 and 3.6.x through 3.6.1.1 on the Clean Access Manager (CAM) allows remote attackers to bypass authentication and download arbitrary manual database backups by guessing the snapshot filename using brute force, then making a direct…

  • CVE-2006-4097Dec 31, 2006
    risk 0.00cvss —epss 0.04

    Multiple unspecified vulnerabilities in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allow remote attackers to cause a denial of service (crash) via a crafted RADIUS Access-Request packet. NOTE: it…

  • CVE-2006-5808Nov 8, 2006
    risk 0.00cvss —epss 0.00

    The installation of Cisco Secure Desktop (CSD) before 3.1.1.45 uses insecure default permissions (all users full control) for the CSD directory and its parent directory, which allow local users to gain privileges by replacing CSD executables, aka "Local Privilege Escalation".

  • CVE-2006-5807Nov 8, 2006
    risk 0.00cvss —epss 0.00

    Cisco Secure Desktop (CSD) before 3.1.1.45 allows local users to escape out of the secure desktop environment by using certain applications that switch to the default desktop, aka "System Policy Evasion".

  • CVE-2006-5806Nov 8, 2006
    risk 0.00cvss —epss 0.00

    SSL VPN Client in Cisco Secure Desktop before 3.1.1.45, when configured to spawn a web browser after a successful connection, stores sensitive browser session information in a directory outside of the CSD vault and does not restrict the user from saving files outside of the…

  • CVE-2006-5660Nov 3, 2006
    risk 0.00cvss —epss 0.04

    Cisco Security Agent Management Center (CSAMC) 5.1 before 5.1.0.79 does not properly handle certain LDAP error messages, which allows remote attackers to bypass authentication requirements via an empty password when using an external LDAP server.

  • CVE-2006-5553Oct 26, 2006
    risk 0.00cvss —epss 0.03

    Cisco Security Agent (CSA) for Linux 4.5 before 4.5.1.657 and 5.0 before 5.0.0.193, as used by Unified CallManager (CUCM) and Unified Presence Server (CUPS), allows remote attackers to cause a denial of service (resource consumption) via a port scan with certain options.

  • CVE-2006-5394Oct 18, 2006
    risk 0.00cvss —epss 0.00

    The default configuration of Cisco Secure Desktop (CSD) has an unchecked "Disable printing" box in Secure Desktop Settings, which might allow local users to read data that was sent to a printer during another user's SSL VPN session.

  • CVE-2006-5288Oct 13, 2006
    risk 0.00cvss —epss 0.04

    Cisco 2700 Series Wireless Location Appliances before 2.1.34.0 have a default administrator username "root" and password "password," which allows remote attackers to obtain administrative privileges, aka Bug ID CSCsb92893.

  • CVE-2006-4982Sep 26, 2006
    risk 0.00cvss —epss 0.00

    Cisco NAC maintains an exception list that does not record device properties other than MAC address, which allows physically proximate attackers to bypass control methods and join a local network by spoofing the MAC address of a different type of device, as demonstrated by using…

  • CVE-2006-4983Sep 26, 2006
    risk 0.00cvss —epss 0.01

    Cisco NAC allows quarantined devices to communicate over the network with (1) DNS, (2) DHCP, and (3) EAPoUDP, which allows attackers to bypass control methods by tunneling network traffic through one of these protocols.

  • CVE-2006-4950Sep 23, 2006
    risk 0.00cvss —epss 0.06

    Cisco IOS 12.2 through 12.4 before 20060920, as used by Cisco IAD2430, IAD2431, and IAD2432 Integrated Access Devices, the VG224 Analog Phone Gateway, and the MWR 1900 and 1941 Mobile Wireless Edge Routers, is incorrectly identified as supporting DOCSIS, which allows remote…

  • CVE-2006-4909Sep 21, 2006
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in Cisco Guard DDoS Mitigation Appliance before 5.1(6), when anti-spoofing is enabled, allows remote attackers to inject arbitrary web script or HTML via certain character sequences in a URL that are not properly handled when the…

  • CVE-2006-4911Sep 21, 2006
    risk 0.00cvss —epss 0.04

    Unspecified vulnerability in Cisco IPS 5.0 before 5.0(6p2) and 5.1 before 5.1(2), when running in inline or promiscuous mode, allows remote attackers to bypass traffic inspection via a "crafted sequence of fragmented IP packets".

  • CVE-2006-4910Sep 21, 2006
    risk 0.00cvss —epss 0.04

    The web administration interface (mainApp) to Cisco IDS before 4.1(5c), and IPS 5.0 before 5.0(6p1) and 5.1 before 5.1(2) allows remote attackers to cause a denial of service (unresponsive device) via a crafted SSLv2 Client Hello packet.

  • CVE-2006-4774Sep 14, 2006
    risk 0.00cvss —epss 0.05

    The VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(19) allows remote attackers to cause a denial of service by sending a VTP version 1 summary frame with a VTP version field value of 2.

  • CVE-2006-4775Sep 14, 2006
    risk 0.00cvss —epss 0.05

    The VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(19) and CatOS allows remote attackers to cause a denial of service by sending a VTP update with a revision value of 0x7FFFFFFF, which is incremented to 0x80000000 and is interpreted as a negative number in a signed…

  • CVE-2006-4650Sep 9, 2006
    risk 0.00cvss —epss 0.03

    Cisco IOS 12.0, 12.1, and 12.2, when GRE IP tunneling is used and the RFC2784 compliance fixes are missing, does not verify the offset field of a GRE packet during decapsulation, which leads to an integer overflow that references data from incorrect memory locations, which…

  • CVE-2006-4430Aug 29, 2006
    risk 0.00cvss —epss 0.02

    The Cisco Network Admission Control (NAC) 3.6.4.1 and earlier allows remote attackers to prevent installation of the Cisco Clean Access (CCA) Agent and bypass local and remote protection mechanisms by modifying (1) the HTTP User-Agent header or (2) the behavior of the TCP/IP…

  • CVE-2006-4352Aug 25, 2006
    risk 0.00cvss —epss 0.01

    The ArrowPoint cookie functionality for Cisco 11000 series Content Service Switches specifies an internal IP address if the administrator does not specify a string option, which allows remote attackers to obtain sensitive information.

  • CVE-2006-4312Aug 23, 2006
    risk 0.00cvss —epss 0.00

    Cisco PIX 500 Series Security Appliances and ASA 5500 Series Adaptive Security Appliances, when running 7.0(x) up to 7.0(5) and 7.1(x) up to 7.1(2.4), and Firewall Services Module (FWSM) 3.1(x) up to 3.1(1.6), causes the EXEC password, local user passwords, and the enable…

  • CVE-2006-4194Aug 17, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in Cisco PIX 500 Series Security Appliances allows remote attackers to send arbitrary UDP packets to intranet devices via unspecified vectors involving Session Initiation Protocol (SIP) fixup commands, a different issue than CVE-2006-4032. NOTE: the…

  • CVE-2006-4032Aug 9, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in Cisco IOS CallManager Express (CME) allows remote attackers to gain sensitive information (user names) from the Session Initiation Protocol (SIP) user directory via certain SIP messages, aka bug CSCse92417.

  • CVE-2006-3732Jul 21, 2006
    risk 0.00cvss —epss 0.01

    Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1 ships with an Oracle database that contains several default accounts and passwords, which allows attackers to obtain sensitive information.

  • CVE-2006-3596Jul 18, 2006
    risk 0.00cvss —epss 0.02

    The device driver for Intel-based gigabit network adapters in Cisco Intrusion Prevention System (IPS) 5.1(1) through 5.1(p1), as installed on various Cisco Intrusion Prevention System 42xx appliances, allows remote attackers to cause a denial of service (kernel panic and…

  • CVE-2006-3593Jul 18, 2006
    risk 0.00cvss —epss 0.01

    The command line interface (CLI) in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows local users to overwrite arbitrary files by redirecting a command's output to a file or folder, aka bug CSCse31704.

  • CVE-2006-3594Jul 18, 2006
    risk 0.00cvss —epss 0.04

    Buffer overflow in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows remote attackers to execute arbitrary code via a long hostname in a SIP request, aka bug CSCsd96542.

  • CVE-2006-3592Jul 18, 2006
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the command line interface (CLI) in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows local users to execute arbitrary commands with elevated privileges via unspecified vectors, involving "certain CLI commands," aka bug CSCse11005.

  • CVE-2006-3595Jul 18, 2006
    risk 0.00cvss —epss 0.04

    The default configuration of IOS HTTP server in Cisco Router Web Setup (CRWS) before 3.3.0 build 31 does not require credentials, which allows remote attackers to access the server with arbitrary privilege levels, aka bug CSCsa78190.

  • CVE-2006-3424Jul 7, 2006
    risk 0.00cvss —epss 0.03

    Multiple buffer overflows in WebEx Downloader ActiveX Control, possibly in versions before November 2005, allow remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2006-3288Jun 28, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the TFTP server in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51), when configured to use a directory path name that contains a space character, allows remote authenticated users to read and overwrite arbitrary files via…

  • CVE-2006-3289Jun 28, 2006
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the login page of the HTTP interface for the Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a "malicious URL".

  • CVE-2006-3291Jun 28, 2006
    risk 0.00cvss —epss 0.04

    The web interface on Cisco IOS 12.3(8)JA and 12.3(8)JA1, as used on the Cisco Wireless Access Point and Wireless Bridge, reconfigures itself when it is changed to use the "Local User List Only (Individual Passwords)" setting, which removes all security and password…

Page 136 of 142