Vulnerability index

Browse CVEs

3,250 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Unified Contact Center Express Editor Software MEDIUM 6.8
CVE-2014-0745

Cross-site request forgery (CSRF) vulnerability in the Unified Serviceability subsystem in Cisco Unified Contact Center Express (Unified CCX) allows …

Mitigation only
Fix from $1,600 2014-02-27
Unified Sip Phone 3905 HIGH 10.0
CVE-2014-0721

The Cisco Unified SIP Phone 3905 with firmware before 9.4(1) allows remote attackers to obtain root access via a session on the test interface on TCP…

Mitigation only
Fix from $1,950 2014-02-22
Firewall Services Module Software HIGH 7.1
CVE-2014-0710

Race condition in the cut-through proxy feature in Cisco Firewall Services Module (FWSM) Software 3.x before 3.2(28) and 4.x before 4.1(15) allows re…

Mitigation only
Fix from $1,950 2014-02-22
Ips Sensor Software HIGH 7.1
CVE-2014-0718

The produce-verbose-alert feature in Cisco IPS Software 7.1 before 7.1(8)E4 and 7.2 before 7.2(2)E4 allows remote attackers to cause a denial of serv…

Mitigation only
Fix from $1,950 2014-02-22
Unified Communications Manager HIGH 7.5
CVE-2014-0727

SQL injection vulnerability in the CallManager Interactive Voice Response (CMIVR) interface in Cisco Unified Communications Manager (UCM) allows remo…

Mitigation only
Fix from $1,950 2014-02-13
Unified Communications Manager HIGH 7.5
CVE-2014-0729

SQL injection vulnerability in the Enterprise Mobility Application (EMApp) interface in Cisco Unified Communications Manager (UCM) allows remote atta…

Mitigation only
Fix from $1,950 2014-02-13
Unified Communications Manager MEDIUM 5.0
CVE-2014-0722

The log4jinit web application in Cisco Unified Communications Manager (UCM) does not properly validate authentication, which allows remote attackers …

Mitigation only
Fix from $1,600 2014-02-13
Unified Communications Manager MEDIUM 5.0
CVE-2014-0725

Cisco Unified Communications Manager (UCM) does not require authentication for reading WAR files, which allows remote attackers to obtain sensitive i…

Mitigation only
Fix from $1,600 2014-02-13
Secure Access Control System MEDIUM 5.5
CVE-2014-0678

The portal interface in Cisco Secure Access Control System (ACS) does not properly manage sessions, which allows remote authenticated users to hijack…

Mitigation only
Fix from $1,600 2014-01-25
Video Surveillance Operations Manager MEDIUM 6.8
CVE-2014-0674

Cisco Video Surveillance Operations Manager (VSOM) does not require authentication for MySQL database connections, which allows remote attackers to o…

Mitigation only
Fix from $1,600 2014-01-24
Telepresence Video Communication Server MEDIUM 6.4
CVE-2014-0675

The Expressway component in Cisco TelePresence Video Communication Server (VCS) uses the same default X.509 certificate across different customers' i…

Mitigation only
Fix from $1,600 2014-01-23
Telepresence Video Communication Server Software HIGH 7.1
CVE-2014-0662

The SIP module in Cisco TelePresence Video Communication Server (VCS) before 8.1 allows remote attackers to cause a denial of service (process failur…

Mitigation only
Fix from $1,950 2014-01-22
Nx Os MEDIUM 6.8
CVE-2014-0676

Cisco NX-OS allows local users to bypass intended TACACS+ command restrictions via a series of multiple commands, aka Bug ID CSCum47367.

Mitigation only
Fix from $1,600 2014-01-22
Nx Os MEDIUM 5.0
CVE-2014-0677

The Label Distribution Protocol (LDP) functionality in Cisco NX-OS allows remote attackers to cause a denial of service (temporary LDP session outage…

Mitigation only
Fix from $1,600 2014-01-22
Mediasense MEDIUM 5.8
CVE-2014-0671

Open redirect vulnerability in Cisco MediaSense allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an …

Mitigation only
Fix from $1,600 2014-01-22
Asr 5000 Series Software MEDIUM 5.0
CVE-2014-0669

The Wireless Session Protocol (WSP) feature in the Gateway GPRS Support Node (GGSN) component on Cisco ASR 5000 series devices allows remote attacker…

Mitigation only
Fix from $1,600 2014-01-22
Secure Access Control System MEDIUM 6.3
CVE-2014-0667

The RMI interface in Cisco Secure Access Control System (ACS) does not properly enforce authorization requirements, which allows remote authenticated…

Mitigation only
Fix from $1,600 2014-01-16
Unity Connection MEDIUM 6.8
CVE-2014-0664

The server in Cisco Unity Connection allows remote authenticated users to cause a denial of service (CPU consumption) via unspecified IMAP commands, …

Mitigation only
Fix from $1,600 2014-01-10
Unified Ip Phones 9900 Series Firmware MEDIUM 5.4
CVE-2014-0658

Cisco 9900 Unified IP phones allow remote attackers to cause a denial of service (unregistration) via a crafted SIP header, aka Bug ID CSCul24898.

Mitigation only
Fix from $1,600 2014-01-10
Unified Presence Server MEDIUM 6.5
CVE-2013-6983

SQL injection vulnerability in the web interface in Cisco Unified Presence Server allows remote authenticated users to execute arbitrary SQL commands…

Mitigation only
Fix from $1,600 2013-12-31
Ios Xe MEDIUM 5.4
CVE-2013-6979

The VTY authentication implementation in Cisco IOS XE 03.02.xxSE and 03.03.xxSE incorrectly relies on the Linux-IOS internal-network configuration, w…

Mitigation only
Fix from $1,600 2013-12-23
Epc3925 MEDIUM 6.8
CVE-2013-6976

Cross-site request forgery (CSRF) vulnerability in goform/Quick_setup on Cisco EPC3925 devices allows remote attackers to hijack the authentication o…

No fix yet
Fix from $1,600 2013-12-19
Cisco Ons 15454 System Software MEDIUM 5.0
CVE-2013-6701

The tNetTaskLimit process on the Transport Node Controller (TNC) on Cisco ONS 15454 devices with software 9.6 and earlier does not properly prioritiz…

Mitigation only
Fix from $1,600 2013-12-18
Webex Training Center MEDIUM 5.8
CVE-2013-6966

Open redirect vulnerability in Cisco WebEx Training Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing atta…

Mitigation only
Fix from $1,600 2013-12-17
Webex Training Center MEDIUM 6.8
CVE-2013-6710

Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Training Center allows remote attackers to hijack the authentication of unspecified vi…

Mitigation only
Fix from $1,600 2013-12-14
Webex Sales Center MEDIUM 5.8
CVE-2013-6959

Open redirect vulnerability in Cisco WebEx Sales Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks…

Mitigation only
Fix from $1,600 2013-12-14
Webex Sales Center MEDIUM 5.8
CVE-2013-6967

Open redirect vulnerability in the mobile-browser subsystem in Cisco WebEx Sales Center allows remote attackers to redirect users to arbitrary web si…

No fix yet
Fix from $1,600 2013-12-14
Webex Training Center MEDIUM 5.8
CVE-2013-6971

Open redirect vulnerability in Cisco WebEx Training Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing atta…

Mitigation only
Fix from $1,600 2013-12-14
Webex Training Center MEDIUM 5.0
CVE-2013-6965

The registration component in Cisco WebEx Training Center provides the training-session URL before e-mail confirmation is completed, which allows rem…

Mitigation only
Fix from $1,600 2013-12-14
Webex Training Center MEDIUM 5.0
CVE-2013-6968

Cisco WebEx Training Center provides different error messages for registration attempts depending on whether the e-mail address exists, which allows …

Mitigation only
Fix from $1,600 2013-12-14