Vulnerability index

Browse CVEs

3,250 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Identity Services Engine Software MEDIUM 5.0
CVE-2014-8017

The periodic-backup feature in Cisco Identity Services Engine (ISE) allows remote attackers to discover backup-encryption passwords via a crafted req…

Mitigation only
Fix from $1,600 2014-12-22
Enterprise Content Delivery System MEDIUM 5.0
CVE-2014-8019

Directory traversal vulnerability in Cisco Enterprise Content Delivery System (ECDS) allows remote attackers to read arbitrary files via a crafted UR…

Mitigation only
Fix from $1,600 2014-12-20
Ironport Email Security Appliances MEDIUM 5.0
CVE-2014-8016

The Cisco IronPort Email Security Appliance (ESA) allows remote attackers to cause a denial of service (CPU consumption) via long Subject headers in …

Mitigation only
Fix from $1,600 2014-12-19
Ios Xr MEDIUM 5.0
CVE-2014-8014

Cisco IOS XR allows remote attackers to cause a denial of service (RSVP process reload) via a malformed RSVP packet, aka Bug ID CSCub63710.

Mitigation only
Fix from $1,600 2014-12-18
Unified Communications Domain Manager MEDIUM 6.5
CVE-2014-8010

The web framework in Cisco Unified Communications Domain Manager 8 allows remote authenticated administrators to execute arbitrary OS commands via cr…

Mitigation only
Fix from $1,600 2014-12-10
Ios Xr MEDIUM 5.0
CVE-2014-8004

Cisco IOS XR allows remote attackers to cause a denial of service (LISP process reload) by establishing many LISP TCP sessions, aka Bug ID CSCuq90378.

Mitigation only
Fix from $1,600 2014-11-25
Unified Communications Manager Im And Presence Service MEDIUM 5.0
CVE-2014-8000

Cisco Unified Communications Manager IM and Presence Service 9.1(1) produces different returned messages for URL requests depending on whether a user…

Mitigation only
Fix from $1,600 2014-11-21
Unified Computing System MEDIUM 6.8
CVE-2014-7996

Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Integrated Management Controller in Cisco Unified Computing System allo…

Mitigation only
Fix from $1,600 2014-11-18
iOS MEDIUM 5.0
CVE-2014-7992EPSS 27%

The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensitive credential information fro…

Mitigation only
Fix from $1,600 2014-11-18
iOS HIGH 7.1
CVE-2014-7998

Cisco IOS on Aironet access points, when "dot11 aaa authenticator" debugging is enabled, allows remote attackers to cause a denial of service via a m…

Mitigation only
Fix from $1,950 2014-11-15
iOS MEDIUM 6.1
CVE-2014-7997

The DHCP implementation in Cisco IOS on Aironet access points does not properly handle error conditions with short leases and unsuccessful lease-rene…

Mitigation only
Fix from $1,600 2014-11-15
B200 M3 MEDIUM 6.8
CVE-2014-7989

Cisco Unified Computing System on B-Series blade servers allows local users to gain shell privileges via a crafted (1) ping6 or (2) traceroute6 comma…

Mitigation only
Fix from $1,600 2014-11-07
Unified Communications Manager MEDIUM 6.5
CVE-2014-3366

SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to execute …

Mitigation only
Fix from $1,600 2014-10-31
iOS MEDIUM 5.0
CVE-2014-3293

Cisco IOS 15.4(3)S0b on ASR901 devices makes incorrect decisions to use the CPU for IPv4 packet processing, which allows remote attackers to cause a …

Mitigation only
Fix from $1,600 2014-10-28
Expressway Software HIGH 7.8
CVE-2014-3368

Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.2 allow remote attackers to cause a denial of service (device r…

Mitigation only
Fix from $1,950 2014-10-19
Expressway Software HIGH 7.1
CVE-2014-3369

The SIP IX implementation in Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allows remote attackers to cau…

Mitigation only
Fix from $1,950 2014-10-19
Telepresence Video Communication Server Software HIGH 7.1
CVE-2014-3370

Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allow remote attackers to cause a denial of service (device…

Mitigation only
Fix from $1,950 2014-10-19
Prime Optical MEDIUM 6.8
CVE-2014-3408

Cross-site scripting (XSS) vulnerability in the web framework in Cisco Prime Optical 10 allows remote attackers to inject arbitrary web script or HTM…

Mitigation only
Fix from $1,600 2014-10-19
Asa HIGH 9.0
CVE-2014-3389

The VPN implementation in Cisco ASA Software 7.2 before 7.2(5.15), 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.6 before 8.6(1…

Mitigation only
Fix from $1,950 2014-10-10
Adaptive Security Appliance Software HIGH 8.3
CVE-2014-3392

The Clientless SSL VPN portal in Cisco ASA Software 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.6 before 8.6(1.15), 9.0 befor…

Mitigation only
Fix from $1,950 2014-10-10
Asa HIGH 7.8
CVE-2014-3382

The SQL*Net inspection engine in Cisco ASA Software 7.2 before 7.2(5.13), 8.2 before 8.2(5.50), 8.3 before 8.3(2.42), 8.4 before 8.4(7.15), 8.5 befor…

Mitigation only
Fix from $1,950 2014-10-10
Asa HIGH 7.8
CVE-2014-3383

The IKE implementation in the VPN component in Cisco ASA Software 9.1 before 9.1(5.1) allows remote attackers to cause a denial of service (device re…

Mitigation only
Fix from $1,950 2014-10-10
Asa HIGH 7.8
CVE-2014-3384

The IKEv2 implementation in Cisco ASA Software 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1) allows remote…

Mitigation only
Fix from $1,950 2014-10-10
Asa HIGH 7.8
CVE-2014-3385

Race condition in the Health and Performance Monitoring (HPM) for ASDM feature in Cisco ASA Software 8.3 before 8.3(2.42), 8.4 before 8.4(7.11), 8.5 …

Mitigation only
Fix from $1,950 2014-10-10
Asa HIGH 7.8
CVE-2014-3386

The GPRS Tunneling Protocol (GTP) inspection engine in Cisco ASA Software 8.2 before 8.2(5.51), 8.4 before 8.4(7.15), 8.7 before 8.7(1.13), 9.0 befor…

Mitigation only
Fix from $1,950 2014-10-10
Asa HIGH 7.8
CVE-2014-3387

The SunRPC inspection engine in Cisco ASA Software 7.2 before 7.2(5.14), 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.5 before…

Mitigation only
Fix from $1,950 2014-10-10
Asa HIGH 7.8
CVE-2014-3388

The DNS inspection engine in Cisco ASA Software 9.0 before 9.0(4.13), 9.1 before 9.1(5.7), and 9.2 before 9.2(2) allows remote attackers to cause a d…

Mitigation only
Fix from $1,950 2014-10-10
Adaptive Security Appliance Software MEDIUM 6.8
CVE-2014-3390

The Virtual Network Management Center (VNMC) policy implementation in Cisco ASA Software 8.7 before 8.7(1.14), 9.2 before 9.2(2.8), and 9.3 before 9.…

Mitigation only
Fix from $1,600 2014-10-10
Adaptive Security Appliance Software MEDIUM 6.8
CVE-2014-3391

Untrusted search path vulnerability in Cisco ASA Software 8.x before 8.4(3), 8.5, and 8.7 before 8.7(1.13) allows local users to gain privileges by p…

Mitigation only
Fix from $1,600 2014-10-10
Adaptive Security Virtual Appliance MEDIUM 5.0
CVE-2014-3394

The Smart Call Home (SCH) implementation in Cisco ASA Software 8.2 before 8.2(5.50), 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 8.7 before 8.7(1.13)…

Mitigation only
Fix from $1,600 2014-10-10