Vulnerability index

Browse CVEs

3,250 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2016-6413 The installation procedure on Cisco Application Policy Infrastructure Controller (APIC) devices 1.3(2f) mishandles binary files, which allows local u… Application Policy Infrastructure Controller Mitigation only Fix from $1,9502016-09-24 MEDIUM 6.5 CVE-2016-6412 The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows man-in-the-mid… iOS Mitigation only Fix from $1,6002016-09-24 HIGH 7.5 CVE-2016-6411 Cisco Firepower Management Center and FireSIGHT System Software 6.0.1 mishandle comparisons between URLs and X.509 certificates, which allows remote … Firesight System Software Mitigation only Fix from $1,9502016-09-24 MEDIUM 6.5 CVE-2016-6410 The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows remote authent… iOS Mitigation only Fix from $1,6002016-09-24 HIGH 7.5 CVE-2016-6409 The Data in Motion (DMo) component in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is enabled, allows remote attackers to cause a denial o… iOS Mitigation only Fix from $1,9502016-09-24 HIGH 7.5 CVE-2016-6408 Cisco Prime Home 5.2.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction w… Prime Home Mitigation only Fix from $1,9502016-09-24 HIGH 7.8 CVE-2016-6414 iox in Cisco IOS, possibly 15.6 and earlier, and IOS XE, possibly 3.18 and earlier, allows local users to execute arbitrary IOx Linux commands on the… iOS Mitigation only Fix from $1,9502016-09-22 CRITICAL 9.8 CVE-2016-6406 Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on Email Security Appliance (ESA)… Email Security Appliance Firmware Mitigation only Fix from $2,3002016-09-22 CRITICAL 9.8 CVE-2016-6374 Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote attackers to execute arbitrary code via a crafted dnslookup command in an HTTP request, ak… Cloud Services Platform 2100 Mitigation only Fix from $2,3002016-09-22 HIGH 7.2 CVE-2016-6373 The web-based GUI in Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote authenticated administrators to execute arbitrary OS commands as root… Cloud Services Platform 2100 Mitigation only Fix from $1,9502016-09-22 HIGH 7.5 CVE-2016-1483 Cisco WebEx Meetings Server 2.6 allows remote attackers to cause a denial of service (CPU consumption) by repeatedly accessing the account-validation… Webex Meetings Server Mitigation only Fix from $1,9502016-09-19 MEDIUM 6.5 CVE-2016-6405 Cisco Fog Director 1.0(0) for IOx allows remote authenticated users to bypass intended access restrictions and write to arbitrary files via the Cartr… Fog Director Mitigation only Fix from $1,6002016-09-18 MEDIUM 6.1 CVE-2016-6404 Cross-site scripting (XSS) vulnerability in the web framework in Cisco IOx Local Manager in IOS 15.5(2)T and IOS XE allows remote attackers to inject… iOS Mitigation only Fix from $1,6002016-09-18 HIGH 7.8 CVE-2016-6402 UCS Manager and UCS 6200 Fabric Interconnects in Cisco Unified Computing System (UCS) through 3.0(2d) allow local users to obtain OS root access via … Unified Computing System Mitigation only Fix from $1,9502016-09-18 MEDIUM 5.3 CVE-2016-1433 Cisco IOS XR 6.0 and 6.0.1 on NCS 6000 devices allows remote attackers to cause a denial of service (OSPFv3 process reload) via crafted OSPFv3 packet… Ios Xr Mitigation only Fix from $1,6002016-09-18 HIGH 8.1 CVE-2016-1482 Cisco WebEx Meetings Server 2.6 allows remote attackers to execute arbitrary commands by injecting these commands into an application script, aka Bug… Webex Meetings Server Mitigation only Fix from $1,9502016-09-17 HIGH 7.5 CVE-2016-6407 Cisco AsyncOS through 9.5.0-444 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (link saturation) by mak… Web Security Appliance Mitigation only Fix from $1,9502016-09-17 MEDIUM 5.3 CVE-2016-6401 Cisco Carrier Routing System (CRS) 5.1 and 5.1.4, as used in CRS Carrier Grade Services for CRS-1 and CRS-3 devices, allows remote attackers to cause… Carrier Routing System Mitigation only Fix from $1,6002016-09-17 HIGH 7.5 CVE-2016-6399 Cisco ACE30 Application Control Engine Module through A5 3.3 and ACE 4700 Application Control Engine appliances through A5 3.3 allow remote attackers… Ace Application Control Engine Module A1 Mitigation only Fix from $1,9502016-09-12 MEDIUM 5.3 CVE-2016-6398 The PPTP server in Cisco IOS 15.5(3)M does not properly initialize packet buffers, which allows remote attackers to obtain sensitive information from… iOS Mitigation only Fix from $1,6002016-09-12 MEDIUM 5.3 CVE-2016-6396 Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1, when certain malware blocking options are enabled, allow remot… Firesight System Software Mitigation only Fix from $1,6002016-09-12 MEDIUM 5.4 CVE-2016-6395 Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Firepower Management Center before 6.1 and FireSIGHT System S… Firesight System Software Mitigation only Fix from $1,6002016-09-12 CRITICAL 9.1 CVE-2016-6394 Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hija… Firesight System Software Mitigation only Fix from $2,3002016-09-12 HIGH 7.5 CVE-2016-6371 Directory traversal vulnerability in the web interface in Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) 10.6(3) and earlier allows remote … Hosted Collaboration Mediation Fulfillment Mitigation only Fix from $1,9502016-09-12 MEDIUM 5.3 CVE-2016-6375 Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow remote attackers to … Wireless Lan Controller Software Mitigation only Fix from $1,6002016-09-12 HIGH 8.1 CVE-2016-6377 Media Origination System Suite Software 2.6 and earlier in Cisco Virtual Media Packager (VMP) allows remote attackers to bypass authentication and ma… Media Origination System Suite Mitigation only Fix from $1,9502016-09-03 HIGH 7.8 CVE-2016-1464EPSS 10% Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to execute arbitrary code via a crafted file, aka Bug I… Webex Wrf Player T29 No fix yet Fix from $1,9502016-09-03 MEDIUM 5.5 CVE-2016-1415EPSS 6% Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to cause a denial of service (application crash) via a … Webex Wrf Player T29 No fix yet Fix from $1,6002016-09-03 MEDIUM 6.5 CVE-2016-6376 The Adaptive Wireless Intrusion Prevention System (wIPS) feature on Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x bef… Wireless Lan Controller Mitigation only Fix from $1,6002016-09-02 CRITICAL 9.8 CVE-2016-1473 Cisco Small Business 220 devices with firmware before 1.0.1.1 have a hardcoded SNMP community, which allows remote attackers to read or modify SNMP o… Small Business 220 Series Smart Plus Switches Mitigation only Fix from $2,3002016-09-02