Vulnerability index

Browse CVEs

1,018 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Email Security Appliance HIGH 7.5
CVE-2016-6372

A vulnerability in the email message and content filtering for malformed Multipurpose Internet Mail Extensions (MIME) headers of Cisco AsyncOS Softwa…

Mitigation only
Fix from $1,950 2016-10-28
Email Security Appliance HIGH 7.5
CVE-2016-6360

A vulnerability in Advanced Malware Protection (AMP) for Cisco Email Security Appliances (ESA) and Web Security Appliances (WSA) could allow an unaut…

Mitigation only
Fix from $1,950 2016-10-28
Email Security Appliance HIGH 7.5
CVE-2016-6358

A vulnerability in local FTP to the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a partial denial of…

Mitigation only
Fix from $1,950 2016-10-28
Email Security Appliance HIGH 7.5
CVE-2016-6356

A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances could allow an unauthenticated, …

Mitigation only
Fix from $1,950 2016-10-28
Email Security Appliance HIGH 7.5
CVE-2016-1481

A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliances could allow an unauthenticated, …

Mitigation only
Fix from $1,950 2016-10-28
Meeting Server CRITICAL 9.1
CVE-2016-6445

A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of the Cisco Meeting Server (CMS) before 2.0.6 and Acano Server befo…

Mitigation only
Fix from $2,300 2016-10-27
Unified Communications Manager MEDIUM 6.5
CVE-2016-6440

The Cisco Unified Communications Manager (CUCM) may be vulnerable to data that can be displayed inside an iframe within a web page, which in turn cou…

Mitigation only
Fix from $1,600 2016-10-27
Adaptive Security Appliance Software HIGH 7.5
CVE-2016-6431

A vulnerability in the local Certificate Authority (CA) feature of Cisco ASA Software before 9.6(1.5) could allow an unauthenticated, remote attacker…

Mitigation only
Fix from $1,950 2016-10-27
Secure Firewall Management Center HIGH 8.8
CVE-2016-6433EPSS 76%

The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users to execute arbitrary command…

No fix yet
Fix from $1,950 2016-10-06
iOS HIGH 7.5
CVE-2016-6422

Cisco IOS 12.2(33)SXJ9 on Supervisor Engine 32 and 720 modules for 6500 and 7600 devices mishandles certain operators, flags, and keywords in TCAM sh…

Mitigation only
Fix from $1,950 2016-10-06
Nx Os MEDIUM 6.5
CVE-2016-1454

Cisco NX-OS 4.0 through 7.3 and 11.0 through 11.2 on 1000v, 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote atta…

Fix: 5.2 / 6.0+
Fix from $1,600 2016-10-06
Unified Contact Center Express HIGH 7.5
CVE-2016-6426

The j_spring_security_switch_user function in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Expres…

Mitigation only
Fix from $1,950 2016-10-05
iOS HIGH 8.1
CVE-2016-6380

The DNS forwarder in Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.15 allows remote attackers to obtain sensitive inform…

Mitigation only
Fix from $1,950 2016-10-05
iOS HIGH 7.5
CVE-2016-6379

Cisco IOS 12.2 and IOS XE 3.14 through 3.16 and 16.1 allow remote attackers to cause a denial of service (device reload) via crafted IP Detail Record…

Mitigation only
Fix from $1,950 2016-10-05
iOS HIGH 7.5
CVE-2016-6384

Cisco IOS 12.2 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.17 and 16.2 allow remote attackers to cause a denial of service (device re…

Fix: after 15.6
Fix from $1,950 2016-10-05
iOS MEDIUM 6.5
CVE-2016-6412

The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows man-in-the-mid…

Mitigation only
Fix from $1,600 2016-09-24
Firesight System Software HIGH 7.5
CVE-2016-6411

Cisco Firepower Management Center and FireSIGHT System Software 6.0.1 mishandle comparisons between URLs and X.509 certificates, which allows remote …

Mitigation only
Fix from $1,950 2016-09-24
iOS MEDIUM 6.5
CVE-2016-6410

The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows remote authent…

Mitigation only
Fix from $1,600 2016-09-24
Cloud Services Platform 2100 CRITICAL 9.8
CVE-2016-6374

Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote attackers to execute arbitrary code via a crafted dnslookup command in an HTTP request, ak…

Mitigation only
Fix from $2,300 2016-09-22
iOS MEDIUM 6.5
CVE-2014-2146

The Zone-Based Firewall (ZBFW) functionality in Cisco IOS, possibly 15.4 and earlier, and IOS XE, possibly 3.13 and earlier, mishandles zone checking…

Fix: after 15.4
Fix from $1,600 2016-09-22
Webex Meetings Server HIGH 7.5
CVE-2016-1483

Cisco WebEx Meetings Server 2.6 allows remote attackers to cause a denial of service (CPU consumption) by repeatedly accessing the account-validation…

Mitigation only
Fix from $1,950 2016-09-19
Fog Director MEDIUM 6.5
CVE-2016-6405

Cisco Fog Director 1.0(0) for IOx allows remote authenticated users to bypass intended access restrictions and write to arbitrary files via the Cartr…

Mitigation only
Fix from $1,600 2016-09-18
Ace Application Control Engine Module A1 HIGH 7.5
CVE-2016-6399

Cisco ACE30 Application Control Engine Module through A5 3.3 and ACE 4700 Application Control Engine appliances through A5 3.3 allow remote attackers…

Mitigation only
Fix from $1,950 2016-09-12
Firesight System Software MEDIUM 5.3
CVE-2016-6396

Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1, when certain malware blocking options are enabled, allow remot…

Mitigation only
Fix from $1,600 2016-09-12
Webex Wrf Player T29 HIGH 7.8
CVE-2016-1464EPSS 10%

Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to execute arbitrary code via a crafted file, aka Bug I…

No fix yet
Fix from $1,950 2016-09-03
Small Business 220 Series Smart Plus Switches HIGH 7.5
CVE-2016-1472

The web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to cause a denial of serv…

Mitigation only
Fix from $1,950 2016-09-02
Webex Meetings Server HIGH 7.5
CVE-2016-1484

Cisco WebEx Meetings Server 2.6 allows remote attackers to bypass intended access restrictions and obtain sensitive application information via unspe…

Mitigation only
Fix from $1,950 2016-08-23
Aironet Access Point Software MEDIUM 6.5
CVE-2016-6361

The Aggregated MAC Protocol Data Unit (AMPDU) implementation on Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.121.0 and 8.3.x b…

Mitigation only
Fix from $1,600 2016-08-22
Ip Phone 8800 Series Firmware HIGH 7.5
CVE-2016-1479

Cisco IP Phone 8800 devices with software 11.0(1) allow remote attackers to cause a denial of service (memory corruption) via a crafted HTTP request,…

Mitigation only
Fix from $1,950 2016-08-22
Application Policy Infrastructure Controller Enterprise Module HIGH 8.8
CVE-2016-1365

The Grapevine update process in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0 allows remote authenticated users …

Mitigation only
Fix from $1,950 2016-08-18