Vulnerability index

Browse CVEs

1,018 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
iOS MEDIUM 5.0
CVE-2012-1367

The MallocLite implementation in Cisco IOS 12.0, 12.2, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (Route Processor cra…

No fix yet
Fix from $1,600 2012-08-06
Anyconnect Secure Mobility Client HIGH 9.3
CVE-2012-2493

The VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 2.x before 2.5 MR6 on Windows, and 2.x before 2…

Mitigation only
Fix from $1,950 2012-06-20
Anyconnect Secure Mobility Client MEDIUM 6.8
CVE-2012-2496

A certain Java applet in the VPN downloader implementation in the WebLaunch feature in Cisco AnyConnect Secure Mobility Client 3.x before 3.0 MR7 on …

Mitigation only
Fix from $1,600 2012-06-20
Ios Xr HIGH 7.8
CVE-2012-2488

Cisco IOS XR before 4.2.1 on ASR 9000 series devices and CRS series devices allows remote attackers to cause a denial of service (packet transmission…

Fix: after 4.2.0
Fix from $1,950 2012-05-31
iOS MEDIUM 6.3
CVE-2011-4231

Cisco IOS 15.1 and 15.2 and IOS XE 3.x, when configured as an IPsec hub with X.509 certificates in use, allows remote authenticated users to cause a …

Mitigation only
Fix from $1,600 2012-05-03
iOS MEDIUM 5.0
CVE-2012-0338

Cisco IOS 12.2 through 12.4 and 15.0 does not recognize the vrf-also keyword during enforcement of access-class commands, which allows remote attacke…

Mitigation only
Fix from $1,600 2012-05-02
iOS MEDIUM 5.0
CVE-2012-0339

Cisco IOS 12.2 through 12.4 and 15.0 does not recognize the vrf-also keyword during enforcement of access-class commands, which allows remote attacke…

Mitigation only
Fix from $1,600 2012-05-02
Ios Xr HIGH 7.8
CVE-2011-3295

The NETIO and IPV4_IO processes in Cisco IOS XR 3.8 through 4.1, as used in Cisco Carrier Routing System and other products, allow remote attackers t…

Mitigation only
Fix from $1,950 2012-05-02
Adaptive Security Appliance Software HIGH 7.8
CVE-2011-4006

The ESMTP inspection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 through 8.5 allows remote attackers to…

Mitigation only
Fix from $1,950 2012-05-02
iOS MEDIUM 5.4
CVE-2011-2586

The HTTP client in Cisco IOS 12.4 and 15.0 allows user-assisted remote attackers to cause a denial of service (device crash) via a malformed HTTP res…

Mitigation only
Fix from $1,600 2012-05-02
iOS MEDIUM 5.4
CVE-2011-4007

Cisco IOS 15.0 and 15.1 and IOS XE 3.x do not properly handle the "set mpls experimental imposition" command, which allows remote attackers to cause …

Mitigation only
Fix from $1,600 2012-05-02
iOS MEDIUM 5.4
CVE-2011-4016

The PPP implementation in Cisco IOS 12.2 and 15.0 through 15.2, when Point-to-Point Termination and Aggregation (PTA) and L2TP are used, allows remot…

Mitigation only
Fix from $1,600 2012-05-02
Unified Contact Center Express MEDIUM 5.0
CVE-2011-2583

Cisco Unified Contact Center Express (aka CCX) 8.0 and 8.5 allows remote attackers to cause a denial of service via network traffic, as demonstrated …

No fix yet
Fix from $1,600 2012-05-02
Carrier Routing System MEDIUM 5.0
CVE-2011-3283

Cisco Carrier Routing System 3.9.1 allows remote attackers to cause a denial of service (Metro subsystem crash) via a fragmented GRE packet, aka Bug …

Patch available
Fix from $1,600 2012-05-02
Adaptive Security Appliance Software MEDIUM 5.0
CVE-2011-3285

CRLF injection vulnerability in /+CSCOE+/logon.html on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 through 8.4 all…

Mitigation only
Fix from $1,600 2012-05-02
iOS MEDIUM 5.0
CVE-2011-4015

Cisco IOS 15.2S allows remote attackers to cause a denial of service (interface queue wedge) via malformed UDP traffic on port 465, aka Bug ID CSCts4…

Mitigation only
Fix from $1,600 2012-05-02
iOS HIGH 7.8
CVE-2012-0385

The Smart Install feature in Cisco IOS 12.2, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (device reload) by sending a m…

Mitigation only
Fix from $1,950 2012-03-29
Adaptive Security Appliance Software HIGH 7.8
CVE-2012-0355

Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with softwar…

Mitigation only
Fix from $1,950 2012-03-15
Firewall Services Module Software HIGH 7.8
CVE-2012-0356

Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500 series devices, with softwar…

Mitigation only
Fix from $1,950 2012-03-15
Adaptive Security Appliance Software HIGH 7.1
CVE-2012-0353

The UDP inspection engine on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6500…

Mitigation only
Fix from $1,950 2012-03-15
Adaptive Security Appliance Software HIGH 7.1
CVE-2012-0354

The Threat Detection feature on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Module (ASASM) in Cisco Catalyst 6…

Mitigation only
Fix from $1,950 2012-03-15
iOS HIGH 7.5
CVE-2011-2057

The cat6000-dot1x component in Cisco IOS 12.2 before 12.2(33)SXI7 does not properly handle (1) a loop between a dot1x enabled port and an open-authen…

Fix: 12.2+
Fix from $1,950 2011-10-22
iOS HIGH 7.5
CVE-2011-2058

The cat6000-dot1x component in Cisco IOS 12.2 before 12.2(33)SXI7 does not properly handle an external loop between a pair of dot1x enabled ports, wh…

Fix: 12.2+
Fix from $1,950 2011-10-22
Anyconnect Secure Mobility Client HIGH 9.3
CVE-2011-2040EPSS 11%

The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.5.3041, and 3.0.x before 3.0.629, on Linu…

Fix: after 2.5.2019
Fix from $1,950 2011-06-02
Anyconnect Secure Mobility Client HIGH 7.6
CVE-2011-2039EPSS 70%

The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.185 on Windows, and on Windows Mobile, …

Fix: after 2.3
Fix from $1,950 2011-06-02
Secure Desktop HIGH 9.3
CVE-2011-0925

The CSDWebInstallerCtrl ActiveX control in CSDWebInstaller.ocx in Cisco Secure Desktop (CSD) allows remote attackers to download an unintended Cisco …

Mitigation only
Fix from $1,950 2011-02-28
Secure Desktop HIGH 9.3
CVE-2011-0926EPSS 7%

A certain ActiveX control in CSDWebInstaller.ocx in Cisco Secure Desktop (CSD) does not properly verify the signature of an unspecified downloaded pr…

Mitigation only
Fix from $1,950 2011-02-25
iOS HIGH 7.1
CVE-2010-4684

Cisco IOS before 15.0(1)XA1, when certain TFTP debugging is enabled, allows remote attackers to cause a denial of service (device crash) via a TFTP c…

Fix: 15.0+
Fix from $1,950 2011-01-07
iOS MEDIUM 5.0
CVE-2010-4687

STCAPP (aka the SCCP telephony control application) on Cisco IOS before 15.0(1)XA1 does not properly handle multiple calls to a shared line, which al…

Fix: 15.0+
Fix from $1,600 2011-01-07
iOS HIGH 7.8
CVE-2009-5038

Cisco IOS before 15.0(1)XA does not properly handle IRC traffic during a specific time period after an initial reload, which allows remote attackers …

Fix: 15.0+
Fix from $1,950 2011-01-07