Vulnerability index

Browse CVEs

3,245 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Identity Services Engine Software MEDIUM 6.8
CVE-2013-3420

Cross-site request forgery (CSRF) vulnerability in the web framework on the Cisco Identity Services Engine (ISE) allows remote attackers to hijack th…

Mitigation only
Fix from $1,600 2013-07-18
Unified Ip Phones 9900 Series Firmware MEDIUM 5.0
CVE-2013-3426

The Serviceability servlet on Cisco 9900 IP phones does not properly restrict paths, which allows remote attackers to read arbitrary files by specify…

Mitigation only
Fix from $1,600 2013-07-18
Intrusion Prevention System HIGH 7.8
CVE-2013-3411

The IDSM-2 drivers in Cisco Intrusion Prevention System (IPS) Software on Cisco Catalyst 6500 devices with an IDSM-2 module allow remote attackers to…

Mitigation only
Fix from $1,950 2013-07-18
Unified Communications Manager HIGH 7.5
CVE-2013-3404

SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows remote attackers to execute arbitrary SQL co…

Mitigation only
Fix from $1,950 2013-07-18
Unified Communications Manager MEDIUM 6.8
CVE-2013-3403

Multiple untrusted search path vulnerabilities in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allow local users to gain privil…

Mitigation only
Fix from $1,600 2013-07-18
Unified Communications Manager MEDIUM 6.8
CVE-2013-3433

Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows local users to gain privileges by le…

Mitigation only
Fix from $1,600 2013-07-18
Unified Communications Manager MEDIUM 6.8
CVE-2013-3434

Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows local users to gain privileges by le…

Mitigation only
Fix from $1,600 2013-07-18
Unified Communications Manager MEDIUM 6.5
CVE-2013-3402

An unspecified function in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to execute arbitrary c…

Mitigation only
Fix from $1,600 2013-07-18
Unified Communications Manager MEDIUM 6.5
CVE-2013-3412

SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to execute arbitra…

Mitigation only
Fix from $1,600 2013-07-18
Secure Access Control System MEDIUM 6.8
CVE-2013-3424

Cross-site request forgery (CSRF) vulnerability in Administration and View pages in Cisco Secure Access Control System (ACS) allows remote attackers …

Mitigation only
Fix from $1,600 2013-07-12
Unified Communications Domain Manager MEDIUM 6.8
CVE-2013-3418

Cisco Unified Communications Domain Manager does not properly allocate memory for GET and POST requests, which allows remote authenticated users to c…

Mitigation only
Fix from $1,600 2013-07-11
Virtualization Experience Client 6000 Series Firmware MEDIUM 6.8
CVE-2013-3408

The firmware on Cisco Virtualization Experience Client 6000 devices sets incorrect operating-system permissions, which allows local users to gain pri…

Mitigation only
Fix from $1,600 2013-07-10
Nx Os MEDIUM 6.8
CVE-2013-3400

The license-installation module in Cisco NX-OS on Nexus 1000V devices allows local users to execute arbitrary commands via crafted "install license" …

Mitigation only
Fix from $1,600 2013-07-10
Content Security Management Appliance MEDIUM 6.8
CVE-2013-3395

Cross-site request forgery (CSRF) vulnerability in the web framework on Cisco IronPort Web Security Appliance (WSA) devices, Email Security Appliance…

Mitigation only
Fix from $1,600 2013-07-02
Desktop Collaboration Experience MEDIUM 6.6
CVE-2013-3399

Buffer overflow in an unspecified Android API on the Cisco Desktop Collaboration Experience DX650 allows attackers to execute arbitrary code via vect…

Mitigation only
Fix from $1,600 2013-07-02
Unified Communications Manager MEDIUM 6.8
CVE-2013-3397

Cross-site request forgery (CSRF) vulnerability in the Unified Serviceability component in Cisco Unified Communications Manager (CUCM) allows remote …

Mitigation only
Fix from $1,600 2013-06-26
Prime Central For Hosted Collaboration Solution MEDIUM 5.0
CVE-2013-3398

The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance provides different responses to requests for arbitrary pat…

Mitigation only
Fix from $1,600 2013-06-26
Adaptive Security Appliance HIGH 7.8
CVE-2013-3382

The Next-Generation Firewall (aka NGFW, formerly CX Context-Aware Security) module 9.x before 9.1.1.9 and 9.1.2.x before 9.1.2.12 for Cisco Adaptive …

Mitigation only
Fix from $1,950 2013-06-26
Jabber MEDIUM 5.0
CVE-2013-3393

The Precision Video Engine component in Cisco Jabber for Windows and Cisco Virtualization Experience Media Engine allows remote attackers to cause a …

Mitigation only
Fix from $1,600 2013-06-26
Asa Cx Context Aware Security Software MEDIUM 5.4
CVE-2013-1203

Cisco ASA CX Context-Aware Security Software allows remote attackers to cause a denial of service (device reload) via crafted TCP packets that appear…

Mitigation only
Fix from $1,600 2013-06-18
Hosted Collaboration Solution MEDIUM 5.0
CVE-2013-3381

Cisco Hosted Collaboration Mediation allows remote attackers to cause a denial of service (CPU consumption) via a flood of malformed UDP packets on p…

Mitigation only
Fix from $1,600 2013-06-12
Telepresence System Software MEDIUM 6.8
CVE-2013-1246

Cisco TelePresence System Software does not properly handle inactive t-shell sessions, which allows remote authenticated users to cause a denial of s…

Mitigation only
Fix from $1,600 2013-05-31
Nx Os MEDIUM 5.8
CVE-2013-1212

The SSL functionality in Cisco NX-OS on the Nexus 1000V does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoo…

Mitigation only
Fix from $1,600 2013-05-29
Nx Os MEDIUM 5.4
CVE-2013-1210

Array index error in the Virtual Ethernet Module (VEM) kernel driver for VMware ESXi in Cisco NX-OS on the Nexus 1000V, when STUN debugging is enable…

Mitigation only
Fix from $1,600 2013-05-29
Nx Os MEDIUM 5.0
CVE-2013-1209

The encryption functionality in the Virtual Supervisor Module (VSM) to Virtual Ethernet Module (VEM) communication component in Cisco NX-OS on the Ne…

Mitigation only
Fix from $1,600 2013-05-29
Nx Os MEDIUM 5.0
CVE-2013-1211

Cisco NX-OS on the Nexus 1000V does not properly handle authentication for Virtual Ethernet Module (VEM) to Virtual Supervisor Module (VSM) communica…

Mitigation only
Fix from $1,600 2013-05-29
Nx Os MEDIUM 5.0
CVE-2013-1213

Cisco NX-OS on the Nexus 1000V does not assign the proper priority to heartbeat messages from a Virtual Ethernet Module (VEM) to a Virtual Supervisor…

Mitigation only
Fix from $1,600 2013-05-29
Nx Os MEDIUM 5.8
CVE-2013-1208

The encryption functionality in Cisco NX-OS on the Nexus 1000V does not properly handle Virtual Supervisor Module (VSM) to Virtual Ethernet Module (V…

Mitigation only
Fix from $1,600 2013-05-29
Webex MEDIUM 5.8
CVE-2012-6399

Cisco WebEx 4.1 on iOS does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of th…

Mitigation only
Fix from $1,600 2013-05-27
Ios Xr MEDIUM 5.0
CVE-2013-1204

Memory leak in the SNMP process in Cisco IOS XR allows remote attackers to cause a denial of service (memory consumption or process reload) by sendin…

Mitigation only
Fix from $1,600 2013-05-23