Vulnerability index

Browse CVEs

221 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2016-9201 A vulnerability in the Zone-Based Firewall feature of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to pass tra… iOS Mitigation only Fix from $1,9502016-12-14 MEDIUM 6.5 CVE-2016-6471 A vulnerability in the web-based management interface of Cisco Firepower Management Center running FireSIGHT System software could allow an authentic… Firesight System Software Mitigation only Fix from $1,6002016-12-14 HIGH 7.5 CVE-2016-6464 A vulnerability in the web management interface of the Cisco Unified Communications Manager IM and Presence Service could allow an unauthenticated, r… Unified Communications Manager Im And Presence Service Mitigation only Fix from $1,9502016-12-14 HIGH 7.5 CVE-2016-6446 A vulnerability in Web Bridge for Cisco Meeting Server could allow an unauthenticated, remote attacker to retrieve memory from a connected server. Mo… Meeting Server Mitigation only Fix from $1,9502016-10-27 MEDIUM 6.5 CVE-2016-6435EPSS 37% The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted parameters, aka Bug … Secure Firewall Management Center No fix yet Fix from $1,6002016-10-06 HIGH 7.5 CVE-2016-1455 Cisco NX-OS before 7.0(3)I2(2e) and 7.0(3)I4 before 7.0(3)I4(1) has an incorrect iptables local-interface configuration, which allows remote attacker… Nx Os Mitigation only Fix from $1,9502016-10-05 MEDIUM 6.5 CVE-2016-6420 Cisco FireSIGHT System Software 4.10.3 through 5.4.0 in Firepower Management Center allows remote authenticated users to bypass authorization checks … Firesight System Software Mitigation only Fix from $1,6002016-10-05 HIGH 7.5 CVE-2016-6415 KEVEPSS 87% The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and… iOS 5.3.0+ Fix from $1,9502016-09-19 MEDIUM 5.3 CVE-2016-6398 The PPTP server in Cisco IOS 15.5(3)M does not properly initialize packet buffers, which allows remote attackers to obtain sensitive information from… iOS Mitigation only Fix from $1,6002016-09-12 CRITICAL 9.8 CVE-2016-1473 Cisco Small Business 220 devices with firmware before 1.0.1.1 have a hardcoded SNMP community, which allows remote attackers to read or modify SNMP o… Small Business 220 Series Smart Plus Switches Mitigation only Fix from $2,3002016-09-02 HIGH 7.5 CVE-2016-6364 The User Data Services (UDS) API implementation in Cisco Unified Communications Manager 11.5 allows remote attackers to bypass intended access restri… Unified Communications Manager Mitigation only Fix from $1,9502016-08-23 HIGH 7.5 CVE-2016-1484 Cisco WebEx Meetings Server 2.6 allows remote attackers to bypass intended access restrictions and obtain sensitive application information via unspe… Webex Meetings Server Mitigation only Fix from $1,9502016-08-23 MEDIUM 6.5 CVE-2016-1477 Cisco Connected Streaming Analytics 1.1.1 allows remote authenticated users to discover a notification service password by reading administrative pag… Connected Streaming Analytics Mitigation only Fix from $1,6002016-08-23 MEDIUM 6.5 CVE-2016-1452 Cisco ASR 5000 devices with software 18.3 through 20.0.0 allow remote attackers to make configuration changes over SNMP by leveraging knowledge of th… Asr 5000 Mitigation only Fix from $1,6002016-07-15 HIGH 8.1 CVE-2016-1337 Cisco EPC3928 devices allow remote attackers to obtain sensitive configuration and credential information by making requests during the early part of… Epc3928 Firmware No fix yet Fix from $1,9502016-07-03 HIGH 7.5 CVE-2016-1427 The System Configuration Protocol (SCP) core messaging interface in Cisco Prime Network Registrar 8.2 before 8.2.3.1 and 8.3 before 8.3.2 allows remo… Prime Network Registrar Mitigation only Fix from $1,9502016-06-18 HIGH 7.5 CVE-2016-1404 Cisco UCS Invicta 4.3, 4.5, and 5.0.1 on Invicta appliances and Invicta Scaling System uses the same hardcoded GnuPG encryption key across different … Ucs Invicta C3124sa Appliance Mitigation only Fix from $1,9502016-05-29 HIGH 7.5 CVE-2016-1410 Cisco WebEx Meeting Center Original Release Base allows remote attackers to obtain sensitive information about username validity by (1) attending or … Webex Meeting Center Mitigation only Fix from $1,9502016-05-28 MEDIUM 5.3 CVE-2016-1378 Cisco IOS before 15.2(2)E1 on Catalyst switches allows remote attackers to obtain potentially sensitive software-version information via a request to… iOS Mitigation only Fix from $1,6002016-04-14 HIGH 7.1 CVE-2016-1360 Cisco Prime LAN Management Solution (LMS) through 4.2.5 uses the same database decryption key across different customers' installations, which allows… Prime Lan Management Solution Mitigation only Fix from $1,9502016-03-12 HIGH 7.5 CVE-2016-1325 The administration interface on Cisco DPC3939B and DPC3941 devices allows remote attackers to obtain sensitive information via a crafted HTTP request… Dpc3939 Wireless Residential Voice Gateway Firmware Mitigation only Fix from $1,9502016-03-09 MEDIUM 5.3 CVE-2016-1357 The password-management administration component in Cisco Policy Suite (CPS) 7.0.1.3, 7.0.2, 7.0.2-att, 7.0.3-att, 7.0.4-att, and 7.5.0 allows remote… Cisco Policy Suite Mitigation only Fix from $1,6002016-03-03 MEDIUM 5.3 CVE-2016-1342 The device login page in Cisco FirePOWER Management Center 5.3 through 6.0.0.1 allows remote attackers to obtain potentially sensitive software-versi… Secure Firewall Management Center Mitigation only Fix from $1,6002016-02-26 MEDIUM 5.8 CVE-2016-1321 Cisco Universal Small Cell devices with firmware R2.12 through R3.5 contain an image-decryption key in flash memory, which allows remote attackers to… Universal Small Cell Firmware Mitigation only Fix from $1,6002016-02-15 MEDIUM 5.3 CVE-2016-1316 Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7, as used in conjunction with Jabber Guest, allows remote attackers to obtain se… Telepresence Video Communication Server Software Mitigation only Fix from $1,6002016-02-09 MEDIUM 5.3 CVE-2016-1295 Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote attackers to obtain sensitive information via an AnyConnect authentication attempt… Adaptive Security Appliance Software Mitigation only Fix from $1,6002016-01-16 MEDIUM 5.9 CVE-2015-6409 Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STARTTLS downgrade attacks and trigger cleartext XMP… Jabber Mitigation only Fix from $1,6002015-12-26 MEDIUM 5.0 CVE-2015-6428 Cisco DPQ3925 devices with EDVA r1 Base allow remote attackers to obtain sensitive information via a crafted HTTP request, aka Bug ID CSCuv03958. Dpq3925 8x4 Docsis 3.0 Wireless Residential Gateway With Embedded Digital Voice Adapter Mitigation only Fix from $1,6002015-12-18 MEDIUM 5.0 CVE-2015-6411 Cisco FirePOWER Management Center 5.4.1.3, 6.0.0, and 6.0.1 provides verbose responses to requests for help files, which allows remote attackers to o… Secure Firewall Management Center Mitigation only Fix from $1,6002015-12-15 MEDIUM 6.8 CVE-2015-6419 Cisco FireSIGHT Management Center with software 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote authenticated users to read arbitrary files via … Firesight System Software Mitigation only Fix from $1,6002015-12-12