Vulnerability index

Browse CVEs

221 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.0 CVE-2015-6368 Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to read files via a crafted HTTP request, ak… Firepower Extensible Operating System Mitigation only Fix from $1,6002015-11-19 MEDIUM 5.0 CVE-2015-6364 Cisco Content Delivery System Manager Software 3.2 on Videoscape Distribution Suite Service Manager allows remote attackers to obtain sensitive infor… Videoscape Distribution Suite Service Manager after 3.2.0 Fix from $1,6002015-11-14 MEDIUM 5.0 CVE-2015-6355 The web interface in Cisco Unified Computing System (UCS) 2.2(5b)A on blade servers allows remote attackers to obtain potentially sensitive version i… Unified Computing System Mitigation only Fix from $1,6002015-11-04 MEDIUM 6.8 CVE-2015-6328 The web framework in Cisco Prime Collaboration Assurance (PCA) 10.5(1) allows remote authenticated users to bypass intended access restrictions and r… Prime Collaboration Assurance Mitigation only Fix from $1,6002015-10-13 MEDIUM 5.0 CVE-2015-6276 Cisco TelePresence IX5000 8.0.3 stores a private key associated with an X.509 certificate under the web root with insufficient access control, which … Telepresence System Software Ix Mitigation only Fix from $1,6002015-09-05 MEDIUM 6.8 CVE-2015-4308 The webGUI configuration-export feature in Cisco Edge Bluebird Operating System 1.2 on Edge 340 devices allows remote authenticated users to obtain s… Edge Bluebird Operating System Mitigation only Fix from $1,6002015-08-19 MEDIUM 5.0 CVE-2015-4229 The web framework in Cisco Unified Communications Domain Manager 8.1(4)ER1 allows remote attackers to obtain sensitive information by visiting a bvsm… Unified Communications Domain Manager Mitigation only Fix from $1,6002015-06-30 MEDIUM 5.0 CVE-2015-4216 The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual A… Content Security Management Virtual Appliance Mitigation only Fix from $1,6002015-06-26 MEDIUM 5.0 CVE-2015-4218 The web-based user interface in Cisco Jabber through 9.6(3) and 9.7 through 9.7(5) on Windows allows remote attackers to obtain sensitive information… Jabber Mitigation only Fix from $1,6002015-06-24 MEDIUM 5.0 CVE-2015-4212 Cisco WebEx Meeting Center allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by discovering credential… Webex Meeting Center No fix yet Fix from $1,6002015-06-24 HIGH 7.5 CVE-2015-4208 Cisco WebEx Meeting Center does not properly restrict the content of URLs in GET requests, which allows remote attackers to obtain sensitive informat… Webex Meeting Center Mitigation only Fix from $1,9502015-06-24 MEDIUM 6.4 CVE-2015-4209 Cisco WebEx Meeting Center does not properly determine authorization for reading a host calendar, which allows remote attackers to obtain sensitive i… Webex Meeting Center Mitigation only Fix from $1,6002015-06-23 MEDIUM 5.0 CVE-2015-4207 Cisco WebEx Meeting Center places a meeting's access number in a URL, which allows remote attackers to obtain sensitive information and bypass intend… Webex Meeting Center Mitigation only Fix from $1,6002015-06-23 MEDIUM 5.0 CVE-2015-4202 Cisco IOS 12.2SCH on uBR10000 router Cable Modem Termination Systems (CMTS) does not properly restrict access to the IP Detail Record (IPDR) service,… iOS Mitigation only Fix from $1,6002015-06-20 MEDIUM 5.0 CVE-2015-4194 The web-based administrative interface in Cisco WebEx Meeting Center provides different error messages for failed login attempts depending on whether… Webex Meeting Center Mitigation only Fix from $1,6002015-06-19 MEDIUM 5.0 CVE-2015-0764 Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to read arbitrary files via a crafted resource request, aka Bug ID CSCus95603. Unified Meetingplace Mitigation only Fix from $1,6002015-06-04 MEDIUM 5.0 CVE-2015-0763 Cisco Unified MeetingPlace 8.6(1.2) does not properly validate session IDs in http URLs, which allows remote attackers to obtain sensitive session in… Unified Meetingplace Mitigation only Fix from $1,6002015-06-04 MEDIUM 5.0 CVE-2015-0745 Cisco Headend System Release allows remote attackers to read temporary script files or archive files, and consequently obtain sensitive information, … Headend Digital Broadband Delivery System Mitigation only Fix from $1,6002015-05-30 MEDIUM 5.0 CVE-2015-0757 The web framework in Cisco Identity Services Engine (ISE) 1.2(1.901) and 1.3(0.722) does not properly implement session handlers, which allows remote… Identity Services Engine Software Mitigation only Fix from $1,6002015-05-29 MEDIUM 5.0 CVE-2015-0628 The proxy engine on Cisco Web Security Appliance (WSA) devices allows remote attackers to bypass intended proxying restrictions via a malformed HTTP … Web Security Appliance Mitigation only Fix from $1,6002015-02-20 MEDIUM 5.0 CVE-2015-0602 The mobility extension on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to obtain sensitive information by s… Unified Ip Phones 9900 Series Firmware after 9.4 Fix from $1,6002015-02-07 MEDIUM 5.0 CVE-2015-0597 The Forgot Password feature in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to enumerate administrative accounts via c… Webex Meetings Server after 1.5 Fix from $1,6002015-02-02 MEDIUM 5.0 CVE-2015-0595 The XMLAPI in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by reading return messages … Webex Meetings Server after 1.5 Fix from $1,6002015-02-02 MEDIUM 6.8 CVE-2014-8008EPSS 8% Absolute path traversal vulnerability in the Real-Time Monitoring Tool (RTMT) API in Cisco Unified Communications Manager (CUCM) allows remote authen… Unified Communications Manager Mitigation only Fix from $1,6002015-01-22 MEDIUM 5.0 CVE-2015-0590 Cisco WebEx Meeting Center allows remote attackers to activate disabled meeting attributes, and consequently obtain sensitive information, by providi… Webex Meeting Center Mitigation only Fix from $1,6002015-01-17 MEDIUM 5.0 CVE-2015-0583 Cisco WebEx Meeting Center does not properly restrict the content of URLs, which allows remote attackers to obtain sensitive information via vectors … Webex Meeting Center Mitigation only Fix from $1,6002015-01-14 MEDIUM 5.0 CVE-2014-8035 The web framework in Cisco WebEx Meetings Server produces different returned messages for URL requests depending on whether a username exists, which … Webex Meetings Server Mitigation only Fix from $1,6002015-01-10 MEDIUM 5.0 CVE-2014-8017 The periodic-backup feature in Cisco Identity Services Engine (ISE) allows remote attackers to discover backup-encryption passwords via a crafted req… Identity Services Engine Software Mitigation only Fix from $1,6002014-12-22 MEDIUM 5.0 CVE-2014-8009 The Management subsystem in Cisco Unified Computing System 2.1(3f) and earlier allows remote attackers to obtain sensitive information by reading log… Unified Computing System after 2.1 Fix from $1,6002014-12-10 MEDIUM 5.0 CVE-2014-7992EPSS 27% The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensitive credential information fro… iOS Mitigation only Fix from $1,6002014-11-18