Vulnerability index

Browse CVEs

3,250 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Jabber MEDIUM 5.9
CVE-2015-6409

Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STARTTLS downgrade attacks and trigger cleartext XMP…

Mitigation only
Fix from $1,600 2015-12-26
Ios Xe MEDIUM 6.5
CVE-2015-6431

Cisco IOS XE 16.1.1 allows remote attackers to cause a denial of service (device reload) via a packet with the 00-00-00-00-00-00 source MAC address, …

Mitigation only
Fix from $1,600 2015-12-23
iOS MEDIUM 5.0
CVE-2015-6429

The IKEv1 state machine in Cisco IOS 15.4 through 15.6 and IOS XE 3.15 through 3.17 allows remote attackers to cause a denial of service (IPsec conne…

Mitigation only
Fix from $1,600 2015-12-19
Dpq3925 8x4 Docsis 3.0 Wireless Residential Gateway With Embedded Digital Voice Adapter MEDIUM 5.0
CVE-2015-6428

Cisco DPQ3925 devices with EDVA r1 Base allow remote attackers to obtain sensitive information via a crafted HTTP request, aka Bug ID CSCuv03958.

Mitigation only
Fix from $1,600 2015-12-18
Firesight System Software MEDIUM 5.0
CVE-2015-6427

Cisco FireSIGHT Management Center allows remote attackers to bypass the HTTP attack detection feature and avoid triggering Snort IDS rules via an SSL…

Mitigation only
Fix from $1,600 2015-12-18
Prime Network Services Controller HIGH 7.2
CVE-2015-6426

Cisco Prime Network Services Controller 3.0 allows local users to bypass intended access restrictions and execute arbitrary commands via additional p…

Mitigation only
Fix from $1,950 2015-12-18
Application Policy Infrastructure Controller HIGH 7.2
CVE-2015-6424

The boot manager in Cisco Application Policy Infrastructure Controller (APIC) 1.1(0.920a) allows local users to bypass intended access restrictions a…

Mitigation only
Fix from $1,950 2015-12-18
Unified Communications Manager MEDIUM 5.0
CVE-2015-6425

The WebApplications Identity Management subsystem in Cisco Unified Communications Manager 10.5(0.98000.88) allows remote attackers to cause a denial …

Mitigation only
Fix from $1,600 2015-12-16
Secure Firewall Management Center MEDIUM 5.0
CVE-2015-6411

Cisco FirePOWER Management Center 5.4.1.3, 6.0.0, and 6.0.1 provides verbose responses to requests for help files, which allows remote attackers to o…

Mitigation only
Fix from $1,600 2015-12-15
Spa500 Firmware HIGH 7.2
CVE-2015-6403

The TFTP implementation on Cisco Small Business SPA30x, SPA50x, SPA51x phones 7.5.7 improperly validates firmware-image file integrity, which allows …

Mitigation only
Fix from $1,950 2015-12-15
Integrated Management Controller Supervisor MEDIUM 6.8
CVE-2015-6399

The Supervisor 1.0.0.0 and 1.0.0.1 in Cisco Integrated Management Controller (IMC) before 2.0(9) allows remote authenticated users to cause a denial …

Mitigation only
Fix from $1,600 2015-12-15
iOS MEDIUM 6.1
CVE-2015-6359

The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS 15.3(3)S0.1 on ASR devices mishandles internal tables, which allow…

Mitigation only
Fix from $1,600 2015-12-15
Epc3928 Docsis 3.0 8x4 Wireless Residential Gateway With Embedded Digital Voice Adapter HIGH 7.5
CVE-2015-6401EPSS 8%

Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allow remote attackers to bypass an intended authentication requirement and execute unspeci…

No fix yet
Fix from $1,950 2015-12-14
Dpq3925 8x4 Docsis 3.0 Wireless Residential Gateway With Embedded Digital Voice Adapter MEDIUM 6.8
CVE-2015-6378

Cross-site request forgery (CSRF) vulnerability on Cisco DPQ3925 devices with EDVA 5.5.2 allows remote attackers to hijack the authentication of arbi…

Mitigation only
Fix from $1,600 2015-12-14
Emergency Responder MEDIUM 6.8
CVE-2015-6405

Cross-site request forgery (CSRF) vulnerability in Cisco Emergency Responder 10.5(1) and 10.5(1a) allows remote attackers to hijack the authenticatio…

Mitigation only
Fix from $1,600 2015-12-13
Prime Collaboration Assurance HIGH 9.0
CVE-2015-6389

Cisco Prime Collaboration Assurance before 11.0 has a hardcoded cmuser account, which allows remote attackers to obtain access by establishing an SSH…

Mitigation only
Fix from $1,950 2015-12-13
Dpc3939 Wireless Residential Voice Gateway Firmware MEDIUM 6.5
CVE-2015-6361

The administrative web interface on Cisco DPC3939 (XB3) devices with firmware 121109aCMCST allows remote authenticated users to execute arbitrary com…

Mitigation only
Fix from $1,600 2015-12-13
Firesight System Software MEDIUM 6.8
CVE-2015-6419

Cisco FireSIGHT Management Center with software 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote authenticated users to read arbitrary files via …

Mitigation only
Fix from $1,600 2015-12-12
Unified Computing System HIGH 7.1
CVE-2015-6415

Cisco Unified Computing System (UCS) 2.2(3f)A on Fabric Interconnect 6200 devices allows remote attackers to cause a denial of service (CPU consumpti…

Mitigation only
Fix from $1,950 2015-12-12
Unity Connection MEDIUM 6.8
CVE-2015-6408

Cross-site request forgery (CSRF) vulnerability in Cisco Unity Connection 11.5(0.98) allows remote attackers to hijack the authentication of arbitrar…

Mitigation only
Fix from $1,600 2015-12-12
Videoscape Distribution Suite Service Manager MEDIUM 6.5
CVE-2015-6417

Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.4.0 and earlier does not always use RBAC for backend database access, which allows rem…

Mitigation only
Fix from $1,600 2015-12-12
Prime Service Catalog MEDIUM 6.5
CVE-2015-6395

Cisco Prime Service Catalog 10.0, 10.0(R2), 10.1, and 11.0 does not properly restrict access to web pages, which allows remote attackers to modify th…

Mitigation only
Fix from $1,600 2015-12-12
Unified Sip Phone 3900 Firmware HIGH 7.8
CVE-2015-6391

Cisco Unified SIP 3905 phones allow remote attackers to cause a denial of service (resource consumption and functionality loss) via a large amount of…

Mitigation only
Fix from $1,950 2015-12-05
Unified Computing System Central Software MEDIUM 5.0
CVE-2015-6388

Cisco Unified Computing System (UCS) Central software 1.3(0.1) allows remote attackers to conduct server-side request forgery (SSRF) attacks via a cr…

Mitigation only
Fix from $1,600 2015-12-05
Ios Xe HIGH 7.2
CVE-2015-6383

Cisco IOS XE 15.4(3)S on ASR 1000 devices improperly loads software packages, which allows local users to bypass license restrictions and obtain cert…

Mitigation only
Fix from $1,950 2015-12-03
Web Security Appliance MEDIUM 5.0
CVE-2015-6386

The passthrough FTP feature on Cisco Web Security Appliance (WSA) devices with software 8.0.7-142 and 8.5.1-021 allows remote attackers to cause a de…

Mitigation only
Fix from $1,600 2015-12-01
iOS HIGH 7.2
CVE-2015-6385

The publish-event event-manager feature in Cisco IOS 15.5(2)S and 15.5(3)S on Cloud Services Router 1000V devices allows local users to execute arbit…

Mitigation only
Fix from $1,950 2015-12-01
Asr 5000 Series Software MEDIUM 5.0
CVE-2015-6382

Cisco ASR 5000 devices with software 16.0(900) allow remote attackers to cause a denial of service (telnetd process restart) via a TELNET connection,…

Mitigation only
Fix from $1,600 2015-11-26
Adaptive Security Appliance Software MEDIUM 6.8
CVE-2015-6379

The XML parser in the management interface in Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote authenticated users to cause a denia…

Mitigation only
Fix from $1,600 2015-11-25
Firepower Extensible Operating System MEDIUM 6.5
CVE-2015-6380

An unspecified script in the web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenti…

Mitigation only
Fix from $1,600 2015-11-24