Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2016-6413
The installation procedure on Cisco Application Policy Infrastructure Controller (APIC) devices 1.3(2f) mishandles binary files, which allows local u…
Application Policy Infrastructure Controller
Mitigation only
MEDIUM 6.5
CVE-2016-6412
The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows man-in-the-mid…
iOS
Mitigation only
HIGH 7.5
CVE-2016-6411
Cisco Firepower Management Center and FireSIGHT System Software 6.0.1 mishandle comparisons between URLs and X.509 certificates, which allows remote …
Firesight System Software
Mitigation only
MEDIUM 6.5
CVE-2016-6410
The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows remote authent…
iOS
Mitigation only
HIGH 7.5
CVE-2016-6409
The Data in Motion (DMo) component in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is enabled, allows remote attackers to cause a denial o…
iOS
Mitigation only
HIGH 7.5
CVE-2016-6408
Cisco Prime Home 5.2.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction w…
Prime Home
Mitigation only
HIGH 7.8
CVE-2016-6414
iox in Cisco IOS, possibly 15.6 and earlier, and IOS XE, possibly 3.18 and earlier, allows local users to execute arbitrary IOx Linux commands on the…
iOS
Mitigation only
CRITICAL 9.8
CVE-2016-6406
Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on Email Security Appliance (ESA)…
Email Security Appliance Firmware
Mitigation only
CRITICAL 9.8
CVE-2016-6374
Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote attackers to execute arbitrary code via a crafted dnslookup command in an HTTP request, ak…
Cloud Services Platform 2100
Mitigation only
HIGH 7.2
CVE-2016-6373
The web-based GUI in Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote authenticated administrators to execute arbitrary OS commands as root…
Cloud Services Platform 2100
Mitigation only
HIGH 7.5
CVE-2016-1483
Cisco WebEx Meetings Server 2.6 allows remote attackers to cause a denial of service (CPU consumption) by repeatedly accessing the account-validation…
Webex Meetings Server
Mitigation only
MEDIUM 6.5
CVE-2016-6405
Cisco Fog Director 1.0(0) for IOx allows remote authenticated users to bypass intended access restrictions and write to arbitrary files via the Cartr…
Fog Director
Mitigation only
MEDIUM 6.1
CVE-2016-6404
Cross-site scripting (XSS) vulnerability in the web framework in Cisco IOx Local Manager in IOS 15.5(2)T and IOS XE allows remote attackers to inject…
iOS
Mitigation only
HIGH 7.8
CVE-2016-6402
UCS Manager and UCS 6200 Fabric Interconnects in Cisco Unified Computing System (UCS) through 3.0(2d) allow local users to obtain OS root access via …
Unified Computing System
Mitigation only
MEDIUM 5.3
CVE-2016-1433
Cisco IOS XR 6.0 and 6.0.1 on NCS 6000 devices allows remote attackers to cause a denial of service (OSPFv3 process reload) via crafted OSPFv3 packet…
Ios Xr
Mitigation only
HIGH 8.1
CVE-2016-1482
Cisco WebEx Meetings Server 2.6 allows remote attackers to execute arbitrary commands by injecting these commands into an application script, aka Bug…
Webex Meetings Server
Mitigation only
HIGH 7.5
CVE-2016-6407
Cisco AsyncOS through 9.5.0-444 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (link saturation) by mak…
Web Security Appliance
Mitigation only
MEDIUM 5.3
CVE-2016-6401
Cisco Carrier Routing System (CRS) 5.1 and 5.1.4, as used in CRS Carrier Grade Services for CRS-1 and CRS-3 devices, allows remote attackers to cause…
Carrier Routing System
Mitigation only
HIGH 7.5
CVE-2016-6399
Cisco ACE30 Application Control Engine Module through A5 3.3 and ACE 4700 Application Control Engine appliances through A5 3.3 allow remote attackers…
Ace Application Control Engine Module A1
Mitigation only
MEDIUM 5.3
CVE-2016-6398
The PPTP server in Cisco IOS 15.5(3)M does not properly initialize packet buffers, which allows remote attackers to obtain sensitive information from…
iOS
Mitigation only
MEDIUM 5.3
CVE-2016-6396
Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1, when certain malware blocking options are enabled, allow remot…
Firesight System Software
Mitigation only
MEDIUM 5.4
CVE-2016-6395
Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Firepower Management Center before 6.1 and FireSIGHT System S…
Firesight System Software
Mitigation only
CRITICAL 9.1
CVE-2016-6394
Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hija…
Firesight System Software
Mitigation only
HIGH 7.5
CVE-2016-6371
Directory traversal vulnerability in the web interface in Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) 10.6(3) and earlier allows remote …
Hosted Collaboration Mediation Fulfillment
Mitigation only
MEDIUM 5.3
CVE-2016-6375
Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow remote attackers to …
Wireless Lan Controller Software
Mitigation only
HIGH 8.1
CVE-2016-6377
Media Origination System Suite Software 2.6 and earlier in Cisco Virtual Media Packager (VMP) allows remote attackers to bypass authentication and ma…
Media Origination System Suite
Mitigation only
HIGH 7.8
CVE-2016-1464EPSS 10%
Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to execute arbitrary code via a crafted file, aka Bug I…
Webex Wrf Player T29
No fix yet
MEDIUM 5.5
CVE-2016-1415EPSS 6%
Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to cause a denial of service (application crash) via a …
Webex Wrf Player T29
No fix yet
MEDIUM 6.5
CVE-2016-6376
The Adaptive Wireless Intrusion Prevention System (wIPS) feature on Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x bef…
Wireless Lan Controller
Mitigation only
CRITICAL 9.8
CVE-2016-1473
Cisco Small Business 220 devices with firmware before 1.0.1.1 have a hardcoded SNMP community, which allows remote attackers to read or modify SNMP o…
Small Business 220 Series Smart Plus Switches
Mitigation only