Vulnerability index

Browse CVEs

221 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Adaptive Security Appliance Software MEDIUM 5.0
CVE-2014-3398

The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to obtain potentially sensitive software-versi…

Mitigation only
Fix from $1,600 2014-10-05
Cloud Portal MEDIUM 5.0
CVE-2014-3351

Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not properly consider whether a session is a problematic NULL session, which all…

Mitigation only
Fix from $1,600 2014-08-29
Nx Os MEDIUM 5.0
CVE-2014-3341

The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages for invalid requests dependin…

Fix: after 7.0
Fix from $1,600 2014-08-19
Webex Meetings Server MEDIUM 5.0
CVE-2014-3304

The OutlookAction Class in Cisco WebEx Meetings Server allows remote attackers to enumerate user accounts by entering crafted URLs and examining the …

Mitigation only
Fix from $1,600 2014-07-28
Webex Meetings Server MEDIUM 5.0
CVE-2014-3301

The ProfileAction controller in Cisco WebEx Meetings Server (CWMS) 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by…

Fix: after 1.5
Fix from $1,600 2014-07-26
Webex Business Suite MEDIUM 5.0
CVE-2014-2199

meetinginfo.do in Cisco WebEx Event Center, WebEx Meeting Center, WebEx Sales Center, WebEx Training Center, WebEx Meetings Server 1.5(.1.131) and ea…

Fix: after 1.5
Fix from $1,600 2014-05-20
Webex Meeting Center MEDIUM 5.0
CVE-2014-0708

WebEx Meeting Center in Cisco WebEx Business Suite does not properly compose URLs for HTTP GET requests, which allows remote attackers to obtain sens…

Mitigation only
Fix from $1,600 2014-03-21
Webex Training Center MEDIUM 5.0
CVE-2013-6968

Cisco WebEx Training Center provides different error messages for registration attempts depending on whether the e-mail address exists, which allows …

Mitigation only
Fix from $1,600 2013-12-14
Webex Meeting Center MEDIUM 5.0
CVE-2013-6970

Cisco WebEx Meeting Center allows remote attackers to obtain sensitive information by reading verbose error messages within server responses, aka Bug…

Mitigation only
Fix from $1,600 2013-12-14
Webex Training Center MEDIUM 5.0
CVE-2013-6972

Cisco WebEx Training Center allows remote attackers to discover session numbers, and bypass host approval for audio-conference attendance, by reading…

Mitigation only
Fix from $1,600 2013-12-14
Webex Training Center MEDIUM 5.0
CVE-2013-6709

The registration component in Cisco WebEx Training Center provides the training-session URL before payment is completed, which allows remote attacker…

Mitigation only
Fix from $1,600 2013-12-14
Prime Data Center Network Manager HIGH 7.8
CVE-2013-5487

DCNM-SAN Server in Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to read arbitrary files via unspecified vecto…

Fix: after 6.1
Fix from $1,950 2013-09-23
Prime Data Center Network Manager HIGH 7.8
CVE-2013-5490

Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to read arbitrary text files via an XML external entity declarat…

Fix: after 6.1
Fix from $1,950 2013-09-23
Mobility Services Engine MEDIUM 5.0
CVE-2013-3469

Cisco Mobility Services Engine does not properly set up the Oracle SSL service, which allows remote attackers to obtain an unauthenticated session to…

Mitigation only
Fix from $1,600 2013-09-04
Prime Central For Hosted Collaboration Solution MEDIUM 5.0
CVE-2013-3398

The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance provides different responses to requests for arbitrary pat…

Mitigation only
Fix from $1,600 2013-06-26
Webex Meetings Server MEDIUM 5.0
CVE-2013-1231

The HTTP implementation in Cisco WebEx Node for MCS and WebEx Meetings Server allows remote attackers to read cache files via a crafted request, aka …

Mitigation only
Fix from $1,600 2013-05-03
Unified Computing System Infrastructure And Unified Computing System Software HIGH 9.3
CVE-2013-1185

The web interface in the Manager component in Cisco Unified Computing System (UCS) 1.x and 2.x before 2.0(2m) allows remote attackers to obtain sensi…

Mitigation only
Fix from $1,950 2013-04-25
Adaptive Security Appliance Software MEDIUM 5.0
CVE-2013-1194

The ISAKMP implementation on Cisco Adaptive Security Appliances (ASA) devices generates different responses for IKE aggressive-mode messages dependin…

Mitigation only
Fix from $1,600 2013-04-18
Anyconnect Secure Mobility Client MEDIUM 5.0
CVE-2012-3094

The VPN downloader in the download_install component in Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495 on Linux accepts arbitrary X.5…

Mitigation only
Fix from $1,600 2012-09-16
Wide Area Application Services MEDIUM 5.0
CVE-2012-1348

Cisco Wide Area Application Services (WAAS) appliances with software 4.4, 5.0, and 5.1 include a one-way hash of a password within output text, which…

Mitigation only
Fix from $1,600 2012-08-06
Unified Meetingplace MEDIUM 5.0
CVE-2011-4232

The web server in Cisco Unified MeetingPlace 6.1 and 8.5 produces different responses for directory queries depending on whether the directory exists…

Mitigation only
Fix from $1,600 2012-05-03
Ciscoworks Common Services MEDIUM 5.0
CVE-2011-2042

The Sybase SQL Anywhere database component in Cisco CiscoWorks Common Services 3.x and 4.x before 4.1 allows remote attackers to obtain potentially s…

Mitigation only
Fix from $1,600 2011-10-22
iOS MEDIUM 5.0
CVE-2011-2059

The ipv6 component in Cisco IOS before 15.1(4)M1.3 allows remote attackers to conduct fingerprinting attacks and obtain potentially sensitive informa…

Fix: 15.1+
Fix from $1,600 2011-10-22
Unified Communications Manager HIGH 10.0
CVE-2011-1643

Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x, 7.x before 7.1(5b)su4, 8.0, and 8.5 before 8.5(1)su2 and Cisco Unified Pre…

Mitigation only
Fix from $1,950 2011-08-29
Rvs4000 MEDIUM 5.0
CVE-2011-1647

The web management interface on the Cisco RVS4000 Gigabit Security Router with software 1.x before 1.3.3.4 and 2.x before 2.0.2.7, and the WRVS4400N …

Mitigation only
Fix from $1,600 2011-05-31
Telepresence System Software HIGH 10.0
CVE-2011-0376

The TFTP implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x, 1.6.0, and 1.6.1 allows remote attackers to obtain …

Mitigation only
Fix from $1,950 2011-02-25
Asa 5500 MEDIUM 5.0
CVE-2010-4354

The remote-access IPSec VPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices, PIX Security Appliances 500 series device…

Mitigation only
Fix from $1,600 2010-11-30
Unified Wireless Network Solution Software HIGH 7.1
CVE-2010-2982

Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 allows remote attackers to discover a group password via a series of SNMP requests,…

Mitigation only
Fix from $1,950 2010-08-10
Digital Media Manager HIGH 7.1
CVE-2010-0572

Cisco Digital Media Manager (DMM) before 5.2 allows remote authenticated users to discover Cisco Digital Media Player credentials via vectors related…

Fix: after 5.1
Fix from $1,950 2010-03-05
Collaboration Server MEDIUM 5.0
CVE-2010-0642EPSS 8%

Cisco Collaboration Server (CCS) 5 allows remote attackers to read the source code of JHTML files via URL encoded characters in the filename extensio…

No fix yet
Fix from $1,600 2010-02-17