Vulnerability index

Browse CVEs

221 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Firepower Extensible Operating System MEDIUM 5.0
CVE-2015-6368

Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to read files via a crafted HTTP request, ak…

Mitigation only
Fix from $1,600 2015-11-19
Videoscape Distribution Suite Service Manager MEDIUM 5.0
CVE-2015-6364

Cisco Content Delivery System Manager Software 3.2 on Videoscape Distribution Suite Service Manager allows remote attackers to obtain sensitive infor…

Fix: after 3.2.0
Fix from $1,600 2015-11-14
Unified Computing System MEDIUM 5.0
CVE-2015-6355

The web interface in Cisco Unified Computing System (UCS) 2.2(5b)A on blade servers allows remote attackers to obtain potentially sensitive version i…

Mitigation only
Fix from $1,600 2015-11-04
Prime Collaboration Assurance MEDIUM 6.8
CVE-2015-6328

The web framework in Cisco Prime Collaboration Assurance (PCA) 10.5(1) allows remote authenticated users to bypass intended access restrictions and r…

Mitigation only
Fix from $1,600 2015-10-13
Telepresence System Software Ix MEDIUM 5.0
CVE-2015-6276

Cisco TelePresence IX5000 8.0.3 stores a private key associated with an X.509 certificate under the web root with insufficient access control, which …

Mitigation only
Fix from $1,600 2015-09-05
Edge Bluebird Operating System MEDIUM 6.8
CVE-2015-4308

The webGUI configuration-export feature in Cisco Edge Bluebird Operating System 1.2 on Edge 340 devices allows remote authenticated users to obtain s…

Mitigation only
Fix from $1,600 2015-08-19
Unified Communications Domain Manager MEDIUM 5.0
CVE-2015-4229

The web framework in Cisco Unified Communications Domain Manager 8.1(4)ER1 allows remote attackers to obtain sensitive information by visiting a bvsm…

Mitigation only
Fix from $1,600 2015-06-30
Content Security Management Virtual Appliance MEDIUM 5.0
CVE-2015-4216

The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual A…

Mitigation only
Fix from $1,600 2015-06-26
Jabber MEDIUM 5.0
CVE-2015-4218

The web-based user interface in Cisco Jabber through 9.6(3) and 9.7 through 9.7(5) on Windows allows remote attackers to obtain sensitive information…

Mitigation only
Fix from $1,600 2015-06-24
Webex Meeting Center MEDIUM 5.0
CVE-2015-4212

Cisco WebEx Meeting Center allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by discovering credential…

No fix yet
Fix from $1,600 2015-06-24
Webex Meeting Center HIGH 7.5
CVE-2015-4208

Cisco WebEx Meeting Center does not properly restrict the content of URLs in GET requests, which allows remote attackers to obtain sensitive informat…

Mitigation only
Fix from $1,950 2015-06-24
Webex Meeting Center MEDIUM 6.4
CVE-2015-4209

Cisco WebEx Meeting Center does not properly determine authorization for reading a host calendar, which allows remote attackers to obtain sensitive i…

Mitigation only
Fix from $1,600 2015-06-23
Webex Meeting Center MEDIUM 5.0
CVE-2015-4207

Cisco WebEx Meeting Center places a meeting's access number in a URL, which allows remote attackers to obtain sensitive information and bypass intend…

Mitigation only
Fix from $1,600 2015-06-23
iOS MEDIUM 5.0
CVE-2015-4202

Cisco IOS 12.2SCH on uBR10000 router Cable Modem Termination Systems (CMTS) does not properly restrict access to the IP Detail Record (IPDR) service,…

Mitigation only
Fix from $1,600 2015-06-20
Webex Meeting Center MEDIUM 5.0
CVE-2015-4194

The web-based administrative interface in Cisco WebEx Meeting Center provides different error messages for failed login attempts depending on whether…

Mitigation only
Fix from $1,600 2015-06-19
Unified Meetingplace MEDIUM 5.0
CVE-2015-0764

Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to read arbitrary files via a crafted resource request, aka Bug ID CSCus95603.

Mitigation only
Fix from $1,600 2015-06-04
Unified Meetingplace MEDIUM 5.0
CVE-2015-0763

Cisco Unified MeetingPlace 8.6(1.2) does not properly validate session IDs in http URLs, which allows remote attackers to obtain sensitive session in…

Mitigation only
Fix from $1,600 2015-06-04
Headend Digital Broadband Delivery System MEDIUM 5.0
CVE-2015-0745

Cisco Headend System Release allows remote attackers to read temporary script files or archive files, and consequently obtain sensitive information, …

Mitigation only
Fix from $1,600 2015-05-30
Identity Services Engine Software MEDIUM 5.0
CVE-2015-0757

The web framework in Cisco Identity Services Engine (ISE) 1.2(1.901) and 1.3(0.722) does not properly implement session handlers, which allows remote…

Mitigation only
Fix from $1,600 2015-05-29
Web Security Appliance MEDIUM 5.0
CVE-2015-0628

The proxy engine on Cisco Web Security Appliance (WSA) devices allows remote attackers to bypass intended proxying restrictions via a malformed HTTP …

Mitigation only
Fix from $1,600 2015-02-20
Unified Ip Phones 9900 Series Firmware MEDIUM 5.0
CVE-2015-0602

The mobility extension on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to obtain sensitive information by s…

Fix: after 9.4
Fix from $1,600 2015-02-07
Webex Meetings Server MEDIUM 5.0
CVE-2015-0597

The Forgot Password feature in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to enumerate administrative accounts via c…

Fix: after 1.5
Fix from $1,600 2015-02-02
Webex Meetings Server MEDIUM 5.0
CVE-2015-0595

The XMLAPI in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by reading return messages …

Fix: after 1.5
Fix from $1,600 2015-02-02
Unified Communications Manager MEDIUM 6.8
CVE-2014-8008EPSS 8%

Absolute path traversal vulnerability in the Real-Time Monitoring Tool (RTMT) API in Cisco Unified Communications Manager (CUCM) allows remote authen…

Mitigation only
Fix from $1,600 2015-01-22
Webex Meeting Center MEDIUM 5.0
CVE-2015-0590

Cisco WebEx Meeting Center allows remote attackers to activate disabled meeting attributes, and consequently obtain sensitive information, by providi…

Mitigation only
Fix from $1,600 2015-01-17
Webex Meeting Center MEDIUM 5.0
CVE-2015-0583

Cisco WebEx Meeting Center does not properly restrict the content of URLs, which allows remote attackers to obtain sensitive information via vectors …

Mitigation only
Fix from $1,600 2015-01-14
Webex Meetings Server MEDIUM 5.0
CVE-2014-8035

The web framework in Cisco WebEx Meetings Server produces different returned messages for URL requests depending on whether a username exists, which …

Mitigation only
Fix from $1,600 2015-01-10
Identity Services Engine Software MEDIUM 5.0
CVE-2014-8017

The periodic-backup feature in Cisco Identity Services Engine (ISE) allows remote attackers to discover backup-encryption passwords via a crafted req…

Mitigation only
Fix from $1,600 2014-12-22
Unified Computing System MEDIUM 5.0
CVE-2014-8009

The Management subsystem in Cisco Unified Computing System 2.1(3f) and earlier allows remote attackers to obtain sensitive information by reading log…

Fix: after 2.1
Fix from $1,600 2014-12-10
iOS MEDIUM 5.0
CVE-2014-7992EPSS 27%

The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensitive credential information fro…

Mitigation only
Fix from $1,600 2014-11-18