Vulnerability index

Browse CVEs

3,250 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Application Policy Infrastructure Controller HIGH 7.8
CVE-2016-6413

The installation procedure on Cisco Application Policy Infrastructure Controller (APIC) devices 1.3(2f) mishandles binary files, which allows local u…

Mitigation only
Fix from $1,950 2016-09-24
iOS MEDIUM 6.5
CVE-2016-6412

The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows man-in-the-mid…

Mitigation only
Fix from $1,600 2016-09-24
Firesight System Software HIGH 7.5
CVE-2016-6411

Cisco Firepower Management Center and FireSIGHT System Software 6.0.1 mishandle comparisons between URLs and X.509 certificates, which allows remote …

Mitigation only
Fix from $1,950 2016-09-24
iOS MEDIUM 6.5
CVE-2016-6410

The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows remote authent…

Mitigation only
Fix from $1,600 2016-09-24
iOS HIGH 7.5
CVE-2016-6409

The Data in Motion (DMo) component in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is enabled, allows remote attackers to cause a denial o…

Mitigation only
Fix from $1,950 2016-09-24
Prime Home HIGH 7.5
CVE-2016-6408

Cisco Prime Home 5.2.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction w…

Mitigation only
Fix from $1,950 2016-09-24
iOS HIGH 7.8
CVE-2016-6414

iox in Cisco IOS, possibly 15.6 and earlier, and IOS XE, possibly 3.18 and earlier, allows local users to execute arbitrary IOx Linux commands on the…

Mitigation only
Fix from $1,950 2016-09-22
Email Security Appliance Firmware CRITICAL 9.8
CVE-2016-6406

Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on Email Security Appliance (ESA)…

Mitigation only
Fix from $2,300 2016-09-22
Cloud Services Platform 2100 CRITICAL 9.8
CVE-2016-6374

Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote attackers to execute arbitrary code via a crafted dnslookup command in an HTTP request, ak…

Mitigation only
Fix from $2,300 2016-09-22
Cloud Services Platform 2100 HIGH 7.2
CVE-2016-6373

The web-based GUI in Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote authenticated administrators to execute arbitrary OS commands as root…

Mitigation only
Fix from $1,950 2016-09-22
Webex Meetings Server HIGH 7.5
CVE-2016-1483

Cisco WebEx Meetings Server 2.6 allows remote attackers to cause a denial of service (CPU consumption) by repeatedly accessing the account-validation…

Mitigation only
Fix from $1,950 2016-09-19
Fog Director MEDIUM 6.5
CVE-2016-6405

Cisco Fog Director 1.0(0) for IOx allows remote authenticated users to bypass intended access restrictions and write to arbitrary files via the Cartr…

Mitigation only
Fix from $1,600 2016-09-18
iOS MEDIUM 6.1
CVE-2016-6404

Cross-site scripting (XSS) vulnerability in the web framework in Cisco IOx Local Manager in IOS 15.5(2)T and IOS XE allows remote attackers to inject…

Mitigation only
Fix from $1,600 2016-09-18
Unified Computing System HIGH 7.8
CVE-2016-6402

UCS Manager and UCS 6200 Fabric Interconnects in Cisco Unified Computing System (UCS) through 3.0(2d) allow local users to obtain OS root access via …

Mitigation only
Fix from $1,950 2016-09-18
Ios Xr MEDIUM 5.3
CVE-2016-1433

Cisco IOS XR 6.0 and 6.0.1 on NCS 6000 devices allows remote attackers to cause a denial of service (OSPFv3 process reload) via crafted OSPFv3 packet…

Mitigation only
Fix from $1,600 2016-09-18
Webex Meetings Server HIGH 8.1
CVE-2016-1482

Cisco WebEx Meetings Server 2.6 allows remote attackers to execute arbitrary commands by injecting these commands into an application script, aka Bug…

Mitigation only
Fix from $1,950 2016-09-17
Web Security Appliance HIGH 7.5
CVE-2016-6407

Cisco AsyncOS through 9.5.0-444 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (link saturation) by mak…

Mitigation only
Fix from $1,950 2016-09-17
Carrier Routing System MEDIUM 5.3
CVE-2016-6401

Cisco Carrier Routing System (CRS) 5.1 and 5.1.4, as used in CRS Carrier Grade Services for CRS-1 and CRS-3 devices, allows remote attackers to cause…

Mitigation only
Fix from $1,600 2016-09-17
Ace Application Control Engine Module A1 HIGH 7.5
CVE-2016-6399

Cisco ACE30 Application Control Engine Module through A5 3.3 and ACE 4700 Application Control Engine appliances through A5 3.3 allow remote attackers…

Mitigation only
Fix from $1,950 2016-09-12
iOS MEDIUM 5.3
CVE-2016-6398

The PPTP server in Cisco IOS 15.5(3)M does not properly initialize packet buffers, which allows remote attackers to obtain sensitive information from…

Mitigation only
Fix from $1,600 2016-09-12
Firesight System Software MEDIUM 5.3
CVE-2016-6396

Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1, when certain malware blocking options are enabled, allow remot…

Mitigation only
Fix from $1,600 2016-09-12
Firesight System Software MEDIUM 5.4
CVE-2016-6395

Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Firepower Management Center before 6.1 and FireSIGHT System S…

Mitigation only
Fix from $1,600 2016-09-12
Firesight System Software CRITICAL 9.1
CVE-2016-6394

Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hija…

Mitigation only
Fix from $2,300 2016-09-12
Hosted Collaboration Mediation Fulfillment HIGH 7.5
CVE-2016-6371

Directory traversal vulnerability in the web interface in Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) 10.6(3) and earlier allows remote …

Mitigation only
Fix from $1,950 2016-09-12
Wireless Lan Controller Software MEDIUM 5.3
CVE-2016-6375

Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow remote attackers to …

Mitigation only
Fix from $1,600 2016-09-12
Media Origination System Suite HIGH 8.1
CVE-2016-6377

Media Origination System Suite Software 2.6 and earlier in Cisco Virtual Media Packager (VMP) allows remote attackers to bypass authentication and ma…

Mitigation only
Fix from $1,950 2016-09-03
Webex Wrf Player T29 HIGH 7.8
CVE-2016-1464EPSS 10%

Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to execute arbitrary code via a crafted file, aka Bug I…

No fix yet
Fix from $1,950 2016-09-03
Webex Wrf Player T29 MEDIUM 5.5
CVE-2016-1415EPSS 6%

Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to cause a denial of service (application crash) via a …

No fix yet
Fix from $1,600 2016-09-03
Wireless Lan Controller MEDIUM 6.5
CVE-2016-6376

The Adaptive Wireless Intrusion Prevention System (wIPS) feature on Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x bef…

Mitigation only
Fix from $1,600 2016-09-02
Small Business 220 Series Smart Plus Switches CRITICAL 9.8
CVE-2016-1473

Cisco Small Business 220 devices with firmware before 1.0.1.1 have a hardcoded SNMP community, which allows remote attackers to read or modify SNMP o…

Mitigation only
Fix from $2,300 2016-09-02