Vulnerability index

Browse CVEs

3,245 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Catos HIGH 9.3
CVE-2003-0216

Unknown vulnerability in Cisco Catalyst 7.5(1) allows local users to bypass authentication and gain access to the enable mode without a password.

Mitigation only
Fix from $1,950 2003-05-12
iOS HIGH 7.5
CVE-2003-0100EPSS 10%

Buffer overflow in Cisco IOS 11.2.x to 12.0.x allows remote attackers to cause a denial of service and possibly execute commands via a large number o…

Mitigation only
Fix from $1,950 2003-03-03
iOS HIGH 7.8
CVE-2002-2315EPSS 10%

Cisco IOS 11.2.x and 12.0.x does not limit the size of its redirect table, which allows remote attackers to cause a denial of service (memory consump…

No fix yet
Fix from $1,950 2002-12-31
As5350 HIGH 7.8
CVE-2002-2379EPSS 6%

Cisco AS5350 IOS 12.2(11)T with access control lists (ACLs) applied and possibly with ssh running allows remote attackers to cause a denial of servic…

No fix yet
Fix from $1,950 2002-12-31
iOS MEDIUM 5.0
CVE-2002-1768

Cisco IOS 11.1 through 12.2, when HSRP support is not enabled, allows remote attackers to cause a denial of service (CPU consumption) via randomly si…

Mitigation only
Fix from $1,600 2002-12-31
iOS MEDIUM 5.0
CVE-2002-2052

Cisco 2611 router running IOS 12.1(6.5), possibly an interim release, allows remote attackers to cause a denial of service via port scans such as (1)…

Mitigation only
Fix from $1,600 2002-12-31
iOS MEDIUM 5.0
CVE-2002-2053

The design of the Hot Standby Routing Protocol (HSRP), as implemented on Cisco IOS 12.1, when using IRPAS, allows remote attackers to cause a denial …

Mitigation only
Fix from $1,600 2002-12-31
Catos MEDIUM 5.0
CVE-2002-2316

Cisco Catalyst 4000 series switches running CatOS 5.5.5, 6.3.5, and 7.1.2 do not always learn MAC addresses from a single initial packet, which cause…

No fix yet
Fix from $1,600 2002-12-31
iOS HIGH 10.0
CVE-2002-1357EPSS 10%

Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers …

Mitigation only
Fix from $1,950 2002-12-23
iOS HIGH 10.0
CVE-2002-1358EPSS 6%

Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of …

Mitigation only
Fix from $1,950 2002-12-23
iOS HIGH 10.0
CVE-2002-1359EPSS 80%

Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service…

Mitigation only
Fix from $1,950 2002-12-23
iOS HIGH 10.0
CVE-2002-1360EPSS 6%

Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, …

Mitigation only
Fix from $1,950 2002-12-23
Secure Access Control Server HIGH 7.5
CVE-2002-0938

Cross-site scripting vulnerability in CiscoSecure ACS 3.0 allows remote attackers to execute arbitrary script or HTML as other web users via the acti…

No fix yet
Fix from $1,950 2002-10-04
Pix Firewall HIGH 7.5
CVE-2002-0954

The encryption algorithms for enable and passwd commands on Cisco PIX Firewall can be executed quickly due to a limited number of rounds, which make …

Mitigation only
Fix from $1,950 2002-10-04
Vpn 3000 Concentrator Series Software HIGH 7.5
CVE-2002-1096

Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.1, allows restricted administrators to obtain user passwords that are stored in plaintext in HT…

Mitigation only
Fix from $1,950 2002-10-04
Vpn 3000 Concentrator Series Software HIGH 7.5
CVE-2002-1097

Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintex…

Mitigation only
Fix from $1,950 2002-10-04
Vpn 3000 Concentrator Series Software HIGH 7.5
CVE-2002-1098

Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, adds an "HTTPS on Public Inbound (XML-Auto)(forward/in)" rule but sets the protocol to "ANY"…

Mitigation only
Fix from $1,950 2002-10-04
Vpn Client HIGH 7.5
CVE-2002-1106

Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.1C, does not properly verify that certificate DN fields match those of …

Mitigation only
Fix from $1,950 2002-10-04
Vpn Client HIGH 7.5
CVE-2002-1107

Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.2B, does not generate sufficiently random numbers, which may make it vu…

Mitigation only
Fix from $1,950 2002-10-04
Voip Phone Cp 7940 MEDIUM 6.4
CVE-2002-0882

The web server for Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allows remote attackers to cause a denial of service (reset) and possibly read s…

Mitigation only
Fix from $1,600 2002-10-04
Voip Phone Cp 7940 MEDIUM 5.0
CVE-2002-0880

Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allow remote attackers to cause a denial of service (crash) via malformed packets as demonstrated b…

Mitigation only
Fix from $1,600 2002-10-04
Vpn 3000 Concentrator Series Software MEDIUM 5.0
CVE-2002-1093

HTML interface for Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.0.3(B) allows remote attackers to cause a denial of service (CPU consumption)…

Mitigation only
Fix from $1,600 2002-10-04
Vpn 3000 Concentrator Series Software MEDIUM 5.0
CVE-2002-1094

Information leaks in Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.5.4 allow remote attackers to obtain potentially sensitive information via …

Mitigation only
Fix from $1,600 2002-10-04
Vpn 3000 Concentrator Series Software MEDIUM 5.0
CVE-2002-1095

Cisco VPN 3000 Concentrator before 2.5.2(F), with encryption enabled, allows remote attackers to cause a denial of service (reload) via a Windows-bas…

Mitigation only
Fix from $1,600 2002-10-04
Vpn 3000 Concentrator Series Software MEDIUM 5.0
CVE-2002-1099

Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to obtain potentially sensitive information without authentication b…

Mitigation only
Fix from $1,600 2002-10-04
Vpn 3000 Concentrator Series Software MEDIUM 5.0
CVE-2002-1100

Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to cause a denial of service (crash) via a long (1) username or (2) …

Mitigation only
Fix from $1,600 2002-10-04
Vpn 3000 Concentrator Series Software MEDIUM 5.0
CVE-2002-1101

Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user name.

Mitigation only
Fix from $1,600 2002-10-04
Vpn 3000 Concentrator Series Software MEDIUM 5.0
CVE-2002-1102

The LAN-to-LAN IPSEC capability for Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.4, allows remote attackers to cause a denial of service via…

Mitigation only
Fix from $1,600 2002-10-04
Vpn Client MEDIUM 5.0
CVE-2002-1104

Cisco Virtual Private Network (VPN) Client software 2.x.x and 3.x before 3.0.5 allows remote attackers to cause a denial of service (crash) via TCP p…

Mitigation only
Fix from $1,600 2002-10-04
Vpn Client MEDIUM 5.0
CVE-2002-1108

Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.6(Rel), when configured with all tunnel mode, can be forced into acknowle…

Mitigation only
Fix from $1,600 2002-10-04