VYPR

Vendor CVEs

Cisco Systems, Inc.

All CVEs

6,961 total · sorted by risk
  • CVE-2004-0013Feb 3, 2004
    risk 0.00cvss epss 0.02

    jabber 1.4.2, 1.4.2a, and possibly earlier versions, does not properly handle SSL connections, which allows remote attackers to cause a denial of service (crash).

  • CVE-2004-1759Jan 21, 2004
    risk 0.00cvss epss 0.02

    Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning.

  • CVE-2004-1760Jan 21, 2004
    risk 0.00cvss epss 0.04

    The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.

  • CVE-2003-0983Jan 5, 2004
    risk 0.00cvss epss 0.02

    Cisco Unity on IBM servers is shipped with default settings that should have been disabled by the manufacturer, which allows local or remote attackers to conduct unauthorized activities via (1) a "bubba" local user account, (2) an open TCP port 34571, or (3) when a local DHCP…

  • CVE-2003-1003Jan 5, 2004
    risk 0.00cvss epss 0.01

    Cisco PIX firewall 5.x.x, and 6.3.1 and earlier, allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when snmp-server is set.

  • CVE-2003-1002Jan 5, 2004
    risk 0.00cvss epss 0.01

    Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when snmp-server is set.

  • CVE-2003-1001Jan 5, 2004
    risk 0.00cvss epss 0.01

    Buffer overflow in the Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial of service (crash and reload) via HTTP auth requests for (1) TACACS+ or (2) RADIUS authentication.

  • CVE-2003-0982Jan 5, 2004
    risk 0.00cvss epss 0.04

    Buffer overflow in the authentication module for Cisco ACNS 4.x before 4.2.11, and 5.x before 5.0.5, allows remote attackers to execute arbitrary code via a long password.

  • CVE-2003-1004Jan 5, 2004
    risk 0.00cvss epss 0.01

    Cisco PIX firewall 6.2.x through 6.2.3, when configured as a VPN Client, allows remote attackers to cause a denial of service (dropped IPSec tunnel connection) via an IKE Phase I negotiation request to the outside interface of the firewall.

  • CVE-2003-1398Dec 31, 2003
    risk 0.00cvss epss 0.02

    Cisco IOS 12.0 through 12.2, when IP routing is disabled, accepts false ICMP redirect messages, which allows remote attackers to cause a denial of service (network routing modification).

  • CVE-2003-1132Dec 31, 2003
    risk 0.00cvss epss 0.02

    The DNS server for Cisco Content Service Switch (CSS) 11000 and 11500, when prompted for a nonexistent AAAA record, responds with response code 3 (NXDOMAIN or "Name Error") instead of response code 0 ("No Error"), which allows remote attackers to cause a denial of service…

  • CVE-2003-0851Dec 1, 2003
    risk 0.00cvss epss 0.05

    OpenSSL 0.9.6k allows remote attackers to cause a denial of service (crash via large recursion) via malformed ASN.1 sequences.

  • CVE-2003-0731Oct 20, 2003
    risk 0.00cvss epss 0.02

    CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to gain administrative privileges via a certain POST request to com.cisco.nm.cmf.servlet.CsAuthServlet, possibly involving the "cmd" parameter with a modifyUser value and a modified "priviledges"…

  • CVE-2003-0732Oct 20, 2003
    risk 0.00cvss epss 0.02

    CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to obtain restricted information and possibly gain administrative privileges by changing the "guest" user to the Admin user on the Modify or delete users pages.

  • CVE-2003-0677Aug 27, 2003
    risk 0.00cvss epss 0.02

    Cisco CSS 11000 routers on the CS800 chassis allow remote attackers to cause a denial of service (CPU consumption or reboot) via a large number of TCP SYN packets to the circuit IP address, aka "ONDM Ping failure."

  • CVE-2003-0512Aug 27, 2003
    risk 0.00cvss epss 0.03

    Cisco IOS 12.2 and earlier generates a "% Login invalid" message instead of prompting for a password when an invalid username is provided, which allows remote attackers to identify valid usernames on the system and conduct brute force password guessing, as reported for the…

  • CVE-2003-0305Jun 9, 2003
    risk 0.00cvss epss 0.01

    The Service Assurance Agent (SAA) in Cisco IOS 12.0 through 12.2, aka Response Time Reporter (RTR), allows remote attackers to cause a denial of service (crash) via malformed RTR packets to port 1967.

  • CVE-2003-0260May 27, 2003
    risk 0.00cvss epss 0.02

    Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7A allow remote attackers to cause a denial of service (slowdown and possibly reload) via a flood of malformed ICMP packets.

  • CVE-2003-0258May 27, 2003
    risk 0.00cvss epss 0.02

    Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 3.5.x through 4.0.REL, when enabling IPSec over TCP for a port on the concentrator, allow remote attackers to reach the private network without authentication.

  • CVE-2003-0259May 27, 2003
    risk 0.00cvss epss 0.02

    Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7 allows remote attackers to cause a denial of service (reload) via a malformed SSH initialization packet.

  • CVE-2003-0216May 12, 2003
    risk 0.00cvss epss 0.02

    Unknown vulnerability in Cisco Catalyst 7.5(1) allows local users to bypass authentication and gain access to the enable mode without a password.

  • CVE-2003-0210May 12, 2003
    risk 0.00cvss epss 0.06

    Buffer overflow in the administration service (CSAdmin) for Cisco Secure ACS before 3.1.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long user parameter to port 2002.

  • CVE-2002-1491Apr 2, 2003
    risk 0.00cvss epss 0.01

    The Cisco VPN 5000 Client for MacOS before 5.2.2 records the most recently used login password in plaintext when saving "Default Connection" settings, which could allow local users to gain privileges.

  • CVE-2002-1556Mar 31, 2003
    risk 0.00cvss epss 0.01

    Cisco ONS15454 and ONS15327 running ONS before 3.4 allows attackers to cause a denial of service (reset) via an HTTP request to the TCC, TCC+ or XTC, in which the request contains an invalid CORBA Interoperable Object Reference (IOR).

  • CVE-2002-1558Mar 31, 2003
    risk 0.00cvss epss 0.03

    Cisco ONS15454 and ONS15327 running ONS before 3.4 have an account for the VxWorks Operating System in the TCC, TCC+ and XTC that cannot be changed or disabled, which allows remote attackers to gain privileges by connecting to the account via Telnet.

  • CVE-2002-1553Mar 31, 2003
    risk 0.00cvss epss 0.02

    Cisco ONS15454 and ONS15327 running ONS before 3.4 allows remote attackers to modify the system configuration and delete files by establishing an FTP connection to the TCC, TCC+ or XTC using a username and password that does not exist.

  • CVE-2002-1554Mar 31, 2003
    risk 0.00cvss epss 0.00

    Cisco ONS15454 and ONS15327 running ONS before 3.4 stores usernames and passwords in cleartext in the image database for the TCC, TCC+ or XTC, which could allow attackers to gain privileges by obtaining the passwords from the image database or a backup.

  • CVE-2002-1555Mar 31, 2003
    risk 0.00cvss epss 0.02

    Cisco ONS15454 and ONS15327 running ONS before 3.4 uses a "public" SNMP community string that cannot be changed, which allows remote attackers to obtain sensitive information.

  • CVE-2002-1557Mar 31, 2003
    risk 0.00cvss epss 0.01

    Cisco ONS15454 and ONS15327 running ONS before 3.4 allows attackers to cause a denial of service (reset to TCC, TCC+, TCCi or XTC) via a malformed HTTP request that does not contain a leading / (slash) character.

  • CVE-2002-2037Dec 31, 2002
    risk 0.00cvss epss 0.01

    The Cisco Media Gateway Controller (MGC) in (1) SC2200 7.4 and earlier, (2) VSC3000 9.1 and earlier, (3) PGW 2200 9.1 and earlier, (4) Billing and Management Server (BAMS) and (5) Voice Services Provisioning Tool (VSPT) runs on default installations of Solaris 2.6 with…

  • CVE-2002-2053Dec 31, 2002
    risk 0.00cvss epss 0.02

    The design of the Hot Standby Routing Protocol (HSRP), as implemented on Cisco IOS 12.1, when using IRPAS, allows remote attackers to cause a denial of service (CPU consumption) via a router with the same IP address as the interface on which HSRP is running, which causes a loop.

  • CVE-2002-2239Dec 31, 2002
    risk 0.00cvss epss 0.02

    The Cisco Optical Service Module (OSM) for the Catalyst 6500 and 7600 series running Cisco IOS 12.1(8)E through 12.1(13.4)E allows remote attackers to cause a denial of service (hang) via a malformed packet.

  • CVE-2002-2052Dec 31, 2002
    risk 0.00cvss epss 0.02

    Cisco 2611 router running IOS 12.1(6.5), possibly an interim release, allows remote attackers to cause a denial of service via port scans such as (1) scanning all ports on a single host and (2) scanning a network of hosts for a single open port through the router. NOTE: the…

  • CVE-2002-2140Dec 31, 2002
    risk 0.00cvss epss 0.02

    Buffer overflow in Cisco PIX Firewall 5.2.x to 5.2.8, 6.0.x to 6.0.3, 6.1.x to 6.1.3, and 6.2.x to 6.2.1 allows remote attackers to cause a denial of service via HTTP traffic authentication using (1) TACACS+ or (2) RADIUS.

  • CVE-2002-1768Dec 31, 2002
    risk 0.00cvss epss 0.02

    Cisco IOS 11.1 through 12.2, when HSRP support is not enabled, allows remote attackers to cause a denial of service (CPU consumption) via randomly sized UDP packets to the Hot Standby Routing Protocol (HSRP) port 1985.

  • CVE-2002-2316Dec 31, 2002
    risk 0.00cvss epss 0.01

    Cisco Catalyst 4000 series switches running CatOS 5.5.5, 6.3.5, and 7.1.2 do not always learn MAC addresses from a single initial packet, which causes unicast traffic to be broadcast across the switch and allows remote attackers to obtain sensitive network information by…

  • CVE-2002-2208Dec 31, 2002
    risk 0.00cvss epss 0.04

    Extended Interior Gateway Routing Protocol (EIGRP), as implemented in Cisco IOS 11.3 through 12.2 and other products, allows remote attackers to cause a denial of service (flood) by sending a large number of spoofed EIGRP neighbor announcements, which results in an ARP storm on…

  • CVE-2002-2139Dec 31, 2002
    risk 0.00cvss epss 0.01

    Cisco PIX Firewall 6.0.3 and earlier, and 6.1.x to 6.1.3, do not delete the duplicate ISAKMP SAs for a user's VPN session, which allows local users to hijack a session via a man-in-the-middle attack.

  • CVE-2002-1360Dec 23, 2002
    risk 0.00cvss epss 0.06

    Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to interactions with the…

  • CVE-2002-1358Dec 23, 2002
    risk 0.00cvss epss 0.06

    Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.

  • CVE-2002-1190Oct 28, 2002
    risk 0.00cvss epss 0.02

    Cisco Unity 2.x and 3.x uses well-known default user accounts, which could allow remote attackers to gain access and place arbitrary calls.

  • CVE-2002-1189Oct 11, 2002
    risk 0.00cvss epss 0.00

    The default configuration of Cisco Unity 2.x and 3.x does not block international operator calls in the predefined restriction tables, which could allow authenticated users to place international calls using call forwarding.

  • CVE-2002-1096Oct 4, 2002
    risk 0.00cvss epss 0.01

    Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.1, allows restricted administrators to obtain user passwords that are stored in plaintext in HTML source code.

  • CVE-2002-1092Oct 4, 2002
    risk 0.00cvss epss 0.01

    Cisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authentication with group accounts and without any user accounts, allows remote VPN clients to log in using PPTP or IPSEC user authentication.

  • CVE-2002-0880Oct 4, 2002
    risk 0.00cvss epss 0.01

    Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allow remote attackers to cause a denial of service (crash) via malformed packets as demonstrated by (1) "jolt", (2) "jolt2", (3) "raped", (4) "hping2", (5) "bloop", (6) "bubonic", (7) "mutant", (8) "trash", and (9) "trash2."

  • CVE-2002-1098Oct 4, 2002
    risk 0.00cvss epss 0.01

    Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, adds an "HTTPS on Public Inbound (XML-Auto)(forward/in)" rule but sets the protocol to "ANY" when the XML filter configuration is enabled, which ultimately allows arbitrary traffic to pass through the concentrator.

  • CVE-2002-1104Oct 4, 2002
    risk 0.00cvss epss 0.02

    Cisco Virtual Private Network (VPN) Client software 2.x.x and 3.x before 3.0.5 allows remote attackers to cause a denial of service (crash) via TCP packets with source and destination ports of 137 (NETBIOS).

  • CVE-2002-1107Oct 4, 2002
    risk 0.00cvss epss 0.02

    Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.2B, does not generate sufficiently random numbers, which may make it vulnerable to certain attacks such as spoofing.

  • CVE-2002-1097Oct 4, 2002
    risk 0.00cvss epss 0.01

    Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintext in the HTML source code for Certificate Management pages.

  • CVE-2002-1099Oct 4, 2002
    risk 0.00cvss epss 0.01

    Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to obtain potentially sensitive information without authentication by directly accessing certain HTML pages.

Page 137 of 140