Vulnerability index

Browse CVEs

3,250 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Ios Xe MEDIUM 5.0
CVE-2014-3403

The Autonomic Networking Infrastructure (ANI) component in Cisco IOS XE does not properly validate certificates, which allows remote attackers to spo…

Mitigation only
Fix from $1,600 2014-10-10
Ios Xr HIGH 7.5
CVE-2014-3396

Cisco IOS XR on ASR 9000 devices does not properly use compression for port-range and address-range encoding, which allows remote attackers to bypass…

Mitigation only
Fix from $1,950 2014-10-05
Adaptive Security Appliance Software MEDIUM 5.0
CVE-2014-3398

The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to obtain potentially sensitive software-versi…

Mitigation only
Fix from $1,600 2014-10-05
Webex Meetings Server MEDIUM 5.0
CVE-2014-3395

Cisco WebEx Meetings Server (WMS) 2.5 allows remote attackers to trigger the download of arbitrary files via a crafted URL, aka Bug ID CSCup10343.

Mitigation only
Fix from $1,600 2014-09-30
Linksys Wrt310n Router Firmware MEDIUM 6.8
CVE-2013-3068

Cross-site request forgery (CSRF) vulnerability in apply.cgi in Linksys WRT310Nv2 2.0.0.1 allows remote attackers to hijack the authentication of adm…

No fix yet
Fix from $1,600 2014-09-29
iOS HIGH 7.8
CVE-2014-3354

Cisco IOS 12.0, 12.2, 12.4, 15.0, 15.1, 15.2, and 15.3 and IOS XE 2.x and 3.x before 3.7.4S; 3.2.xSE and 3.3.xSE before 3.3.2SE; 3.3.xSG and 3.4.xSG …

Mitigation only
Fix from $1,950 2014-09-25
Ios Xe HIGH 7.8
CVE-2014-3355

The metadata flow feature in Cisco IOS 15.1 through 15.3 and IOS XE 3.3.xXO before 3.3.1XO, 3.6.xS and 3.7.xS before 3.7.6S, and 3.8.xS, 3.9.xS, and …

Mitigation only
Fix from $1,950 2014-09-25
Ios Xe HIGH 7.8
CVE-2014-3356

The metadata flow feature in Cisco IOS 15.1 through 15.3 and IOS XE 3.3.xXO before 3.3.1XO, 3.6.xS and 3.7.xS before 3.7.6S, and 3.8.xS, 3.9.xS, and …

Mitigation only
Fix from $1,950 2014-09-25
iOS HIGH 7.8
CVE-2014-3357

Cisco IOS 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.3.xSE before 3.3.2SE, 3.3.xXO before 3.3.1XO, 3.5.xE before 3.5.2E, and 3.11.xS before 3.11.1S allo…

Mitigation only
Fix from $1,950 2014-09-25
iOS HIGH 7.8
CVE-2014-3358

Memory leak in Cisco IOS 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.3.xSE before 3.3.2SE, 3.3.xXO before 3.3.1XO, 3.5.xE before 3.5.2E, and 3.11.xS befo…

Mitigation only
Fix from $1,950 2014-09-25
iOS HIGH 7.8
CVE-2014-3359

Memory leak in Cisco IOS 15.1 through 15.4 and IOS XE 3.4.xS, 3.5.xS, 3.6.xS, and 3.7.xS before 3.7.6S; 3.8.xS, 3.9.xS, and 3.10.xS before 3.10.1S; a…

Mitigation only
Fix from $1,950 2014-09-25
iOS HIGH 7.8
CVE-2014-3360

Cisco IOS 12.4 and 15.0 through 15.4 and IOS XE 3.1.xS, 3.2.xS, 3.3.xS, 3.4.xS, 3.5.xS, 3.6.xS, and 3.7.xS before 3.7.6S; 3.8.xS, 3.9.xS, and 3.10.xS…

Mitigation only
Fix from $1,950 2014-09-25
iOS HIGH 7.1
CVE-2014-3361

The ALG module in Cisco IOS 15.0 through 15.4 does not properly implement SIP over NAT, which allows remote attackers to cause a denial of service (d…

Mitigation only
Fix from $1,950 2014-09-25
Unified Communications Domain Manager Platform MEDIUM 5.0
CVE-2014-3380

Cisco Unified Communications Domain Manager Platform Software 4.4(.3) and earlier allows remote attackers to cause a denial of service (CPU consumpti…

Mitigation only
Fix from $1,600 2014-09-24
Ios Xr MEDIUM 6.1
CVE-2014-3379

Cisco IOS XR 5.1 and earlier on Network Convergence System 6000 devices allows remote attackers to cause a denial of service (NPU and card hang or re…

Mitigation only
Fix from $1,600 2014-09-20
Ios Xr MEDIUM 5.0
CVE-2014-3376

Cisco IOS XR 5.1 and earlier allows remote attackers to cause a denial of service (process reload) via a malformed RSVP packet, aka Bug ID CSCuq12031.

Mitigation only
Fix from $1,600 2014-09-20
Ios Xr MEDIUM 5.0
CVE-2014-3378

tacacsd in Cisco IOS XR 5.1 and earlier allows remote attackers to cause a denial of service (process reload) via a malformed TACACS+ packet, aka Bug…

Mitigation only
Fix from $1,600 2014-09-20
Telepresence System Software HIGH 7.8
CVE-2014-3362

Memory leak in Cisco TelePresence System Edge MXP Series Software F9.3.3 and earlier allows remote attackers to cause a denial of service (management…

Mitigation only
Fix from $1,950 2014-09-12
Cisco Technical Support MEDIUM 5.4
CVE-2014-5868

The Cisco Technical Support (aka com.cisco.swtg_android) application 3.7.1 for Android does not verify X.509 certificates from SSL servers, which all…

Mitigation only
Fix from $1,600 2014-09-11
Transport Gateway Installation Software MEDIUM 6.3
CVE-2014-3346

The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) does not validate an unspeci…

Mitigation only
Fix from $1,600 2014-08-29
Cloud Portal MEDIUM 5.0
CVE-2014-3351

Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not properly consider whether a session is a problematic NULL session, which all…

Mitigation only
Fix from $1,600 2014-08-29
iOS MEDIUM 5.4
CVE-2014-3347

Cisco IOS 15.1(4)M2 on Cisco 1800 ISR devices, when the ISDN Basic Rate Interface is enabled, allows remote attackers to cause a denial of service (d…

Mitigation only
Fix from $1,600 2014-08-28
Transport Gateway Installation Software MEDIUM 5.0
CVE-2014-3345

The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) 4.0 does not properly check …

Mitigation only
Fix from $1,600 2014-08-28
Unified Communications Manager HIGH 8.5
CVE-2014-3338

The CTIManager module in Cisco Unified Communications Manager (CM) 10.0(1), when single sign-on is enabled, does not properly validate Kerberos SSO t…

Mitigation only
Fix from $1,950 2014-08-12
Unified Communications Domain Manager MEDIUM 6.5
CVE-2014-3339

Multiple SQL injection vulnerabilities in the administrative web interface in Cisco Unified Communications Manager (CM) and Cisco Unified Presence Se…

Mitigation only
Fix from $1,600 2014-08-12
iOS HIGH 7.8
CVE-2014-3327

The EnergyWise module in Cisco IOS 12.2, 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.2.xXO, 3.3.xSG, 3.4.xSG, and 3.5.xE before 3.5.3E allows remote atta…

Mitigation only
Fix from $1,950 2014-08-11
Nx Os MEDIUM 5.0
CVE-2014-3330

Cisco NX-OS 6.1(2)I2(1) on Nexus 9000 switches does not properly process packet-drop policy checks for logged packets, which allows remote attackers …

Mitigation only
Fix from $1,600 2014-08-11
Unity Connection HIGH 9.0
CVE-2014-3333

The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticated users to obtain privileged access by conducting an "HTTP Intercept…

Mitigation only
Fix from $1,950 2014-08-11
Unity Connection MEDIUM 6.5
CVE-2014-3336

SQL injection vulnerability in the web framework in Cisco Unity Connection 9.1(2) and earlier allows remote authenticated users to execute arbitrary …

Mitigation only
Fix from $1,600 2014-08-11
Webex Meetings Server MEDIUM 5.0
CVE-2014-3304

The OutlookAction Class in Cisco WebEx Meetings Server allows remote attackers to enumerate user accounts by entering crafted URLs and examining the …

Mitigation only
Fix from $1,600 2014-07-28