Filtered by vendor Cisco
Subscribe
Total
5838 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2013-6684 | 1 Cisco | 1 Wireless Lan Controller | 2013-11-14 | 6.8 MEDIUM | N/A |
The web framework on Cisco Wireless LAN Controller (WLC) devices does not properly validate configuration parameters, which allows remote authenticated users to cause a denial of service via a crafted HTTP request, aka Bug ID CSCuh81011. | |||||
CVE-2013-6682 | 1 Cisco | 1 Adaptive Security Appliance Software | 2013-11-14 | 6.4 MEDIUM | N/A |
The phone-proxy implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier does not properly validate X.509 certificates, which allows remote attackers to cause a denial of service (connection-database corruption) via an invalid entry, aka Bug ID CSCui33299. | |||||
CVE-2013-5552 | 1 Cisco | 2 Content Services Gateway, Ios | 2013-11-14 | 6.4 MEDIUM | N/A |
Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows remote attackers to bypass intended access restrictions via a crafted series of packets, aka Bug ID CSCug90143. | |||||
CVE-2013-5560 | 1 Cisco | 1 Adaptive Security Appliance Software | 2013-11-14 | 5.4 MEDIUM | N/A |
The IPv6 implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1.3 and earlier, when NAT64 or NAT66 is enabled, does not properly process NAT rules, which allows remote attackers to cause a denial of service (device reload) via crafted packets, aka Bug ID CSCue34342. | |||||
CVE-2013-5568 | 1 Cisco | 1 Adaptive Security Appliance Software | 2013-11-14 | 7.1 HIGH | N/A |
The auto-update implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier allows remote attackers to cause a denial of service (device reload) via crafted update data, aka Bug ID CSCui33308. | |||||
CVE-2013-5558 | 1 Cisco | 1 Telepresence Vx Clinical Assistant | 2013-11-08 | 10.0 HIGH | N/A |
The WIL-A module in Cisco TelePresence VX Clinical Assistant 1.2 before 1.21 changes the admin password to an empty password upon a reboot, which makes it easier for remote attackers to obtain access via the administrative interface, aka Bug ID CSCuj17238. | |||||
CVE-2013-5554 | 1 Cisco | 1 Wide Area Application Services Mobile | 2013-11-08 | 7.5 HIGH | N/A |
Directory traversal vulnerability in the web-management interface in the server in Cisco Wide Area Application Services (WAAS) Mobile before 3.5.5 allows remote attackers to upload and execute arbitrary files via a crafted POST request, aka Bug ID CSCuh69773. | |||||
CVE-2013-5553 | 1 Cisco | 1 Ios | 2013-11-08 | 7.8 HIGH | N/A |
Multiple memory leaks in Cisco IOS 15.1 before 15.1(4)M7 allow remote attackers to cause a denial of service (memory consumption or device reload) by sending a crafted SIP message over (1) IPv4 or (2) IPv6, aka Bug IDs CSCuc42558 and CSCug25383. | |||||
CVE-2013-5562 | 1 Cisco | 1 Prime Central For Hosted Collaboration Solution | 2013-11-06 | 5.0 MEDIUM | N/A |
The ITM web server in Cisco Prime Central for Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (temporary HTTP service outage) via a flood of TCP packets, aka Bug ID CSCuh36313. | |||||
CVE-2013-5563 | 1 Cisco | 1 Security Monitoring Analysis And Response System | 2013-11-06 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Query/NewQueryResult.jsp in Cisco Security Monitoring, Analysis and Response System (CS-MARS) allows remote attackers to inject arbitrary web script or HTML via the isnowLatency parameter, aka Bug ID CSCul16173. | |||||
CVE-2013-5564 | 1 Cisco | 1 Prime Central For Hosted Collaboration Solution | 2013-11-06 | 5.0 MEDIUM | N/A |
The Java process in the Impact server in Cisco Prime Central for Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (process crash) via a flood of TCP packets, aka Bug ID CSCug57345. | |||||
CVE-2013-5551 | 1 Cisco | 1 Adaptive Security Appliance Software | 2013-11-05 | 6.3 MEDIUM | N/A |
Cisco Adaptive Security Appliance (ASA) Software, when certain same-security-traffic and management-access options are enabled, allows remote authenticated users to cause a denial of service (stack overflow and device reload) by using the clientless SSL VPN portal for internal-resource browsing, aka Bug ID CSCui51199. | |||||
CVE-2013-5521 | 1 Cisco | 1 Identity Services Engine Software | 2013-10-25 | 5.0 MEDIUM | N/A |
Cisco Identity Services Engine does not properly restrict the creation of guest accounts, which allows remote attackers to cause a denial of service (exhaustion of the account supply) via a series of requests within one session, aka Bug ID CSCue94287. | |||||
CVE-2013-5522 | 1 Cisco | 2 Catalyst 3750-x, Ios | 2013-10-25 | 6.8 MEDIUM | N/A |
Cisco IOS on Catalyst 3750X switches has default Service Module credentials, which makes it easier for local users to gain privileges via a Service Module login, aka Bug ID CSCue92286. | |||||
CVE-2013-5531 | 1 Cisco | 1 Identity Services Engine Software | 2013-10-25 | 5.0 MEDIUM | N/A |
Cisco Identity Services Engine (ISE) 1.x before 1.1.1 allows remote attackers to bypass authentication, and read support-bundle configuration and credentials data, via a crafted session on TCP port 443, aka Bug ID CSCty20405. | |||||
CVE-2013-5549 | 1 Cisco | 1 Ios Xr | 2013-10-25 | 7.1 HIGH | N/A |
Cisco IOS XR 3.8.1 through 4.2.0 does not properly process fragmented packets within the RP-A, RP-B, PRP, and DRP-B route-processor components, which allows remote attackers to cause a denial of service (transmission outage) via (1) IPv4 or (2) IPv6 traffic, aka Bug ID CSCuh30380. | |||||
CVE-2013-5536 | 1 Cisco | 1 Secure Access Control System | 2013-10-24 | 5.0 MEDIUM | N/A |
Cisco Secure Access Control System (ACS) does not properly implement an incoming-packet firewall rule, which allows remote attackers to cause a denial of service (process crash) via a flood of crafted packets, aka Bug ID CSCui51521. | |||||
CVE-2013-5493 | 1 Cisco | 2 Virtualization Experience Client 6000, Virtualization Experience Client 6000 Series Firmware | 2013-10-22 | 6.8 MEDIUM | N/A |
The diagnostic module in the firmware on Cisco Virtualization Experience Client 6000 devices allows local users to bypass intended access restrictions and execute arbitrary commands via unspecified vectors, aka Bug ID CSCug68407. | |||||
CVE-2013-5516 | 1 Cisco | 1 Telepresence Multipoint Switch | 2013-10-22 | 6.3 MEDIUM | N/A |
The Media Snapshot implementation on Cisco TelePresence Multipoint Switch (CTMS) devices allows remote authenticated users to cause a denial of service (device reload) by sending many Media Snapshot requests at the time of a meeting termination, aka Bug ID CSCuh44796. | |||||
CVE-2013-5544 | 1 Cisco | 1 Adaptive Security Appliance Software | 2013-10-22 | 5.4 MEDIUM | N/A |
The VPN authentication functionality in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to cause a denial of service (device reload) by sending many username-from-cert IKE requests, aka Bug ID CSCua91108. |