Vulnerability index

Browse CVEs

3,250 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.8 CVE-2014-0745 Cross-site request forgery (CSRF) vulnerability in the Unified Serviceability subsystem in Cisco Unified Contact Center Express (Unified CCX) allows … Unified Contact Center Express Editor Software Mitigation only Fix from $1,6002014-02-27 HIGH 10.0 CVE-2014-0721 The Cisco Unified SIP Phone 3905 with firmware before 9.4(1) allows remote attackers to obtain root access via a session on the test interface on TCP… Unified Sip Phone 3905 Mitigation only Fix from $1,9502014-02-22 HIGH 7.1 CVE-2014-0710 Race condition in the cut-through proxy feature in Cisco Firewall Services Module (FWSM) Software 3.x before 3.2(28) and 4.x before 4.1(15) allows re… Firewall Services Module Software Mitigation only Fix from $1,9502014-02-22 HIGH 7.1 CVE-2014-0718 The produce-verbose-alert feature in Cisco IPS Software 7.1 before 7.1(8)E4 and 7.2 before 7.2(2)E4 allows remote attackers to cause a denial of serv… Ips Sensor Software Mitigation only Fix from $1,9502014-02-22 HIGH 7.5 CVE-2014-0727 SQL injection vulnerability in the CallManager Interactive Voice Response (CMIVR) interface in Cisco Unified Communications Manager (UCM) allows remo… Unified Communications Manager Mitigation only Fix from $1,9502014-02-13 HIGH 7.5 CVE-2014-0729 SQL injection vulnerability in the Enterprise Mobility Application (EMApp) interface in Cisco Unified Communications Manager (UCM) allows remote atta… Unified Communications Manager Mitigation only Fix from $1,9502014-02-13 MEDIUM 5.0 CVE-2014-0722 The log4jinit web application in Cisco Unified Communications Manager (UCM) does not properly validate authentication, which allows remote attackers … Unified Communications Manager Mitigation only Fix from $1,6002014-02-13 MEDIUM 5.0 CVE-2014-0725 Cisco Unified Communications Manager (UCM) does not require authentication for reading WAR files, which allows remote attackers to obtain sensitive i… Unified Communications Manager Mitigation only Fix from $1,6002014-02-13 MEDIUM 5.5 CVE-2014-0678 The portal interface in Cisco Secure Access Control System (ACS) does not properly manage sessions, which allows remote authenticated users to hijack… Secure Access Control System Mitigation only Fix from $1,6002014-01-25 MEDIUM 6.8 CVE-2014-0674 Cisco Video Surveillance Operations Manager (VSOM) does not require authentication for MySQL database connections, which allows remote attackers to o… Video Surveillance Operations Manager Mitigation only Fix from $1,6002014-01-24 MEDIUM 6.4 CVE-2014-0675 The Expressway component in Cisco TelePresence Video Communication Server (VCS) uses the same default X.509 certificate across different customers' i… Telepresence Video Communication Server Mitigation only Fix from $1,6002014-01-23 HIGH 7.1 CVE-2014-0662 The SIP module in Cisco TelePresence Video Communication Server (VCS) before 8.1 allows remote attackers to cause a denial of service (process failur… Telepresence Video Communication Server Software Mitigation only Fix from $1,9502014-01-22 MEDIUM 6.8 CVE-2014-0676 Cisco NX-OS allows local users to bypass intended TACACS+ command restrictions via a series of multiple commands, aka Bug ID CSCum47367. Nx Os Mitigation only Fix from $1,6002014-01-22 MEDIUM 5.0 CVE-2014-0677 The Label Distribution Protocol (LDP) functionality in Cisco NX-OS allows remote attackers to cause a denial of service (temporary LDP session outage… Nx Os Mitigation only Fix from $1,6002014-01-22 MEDIUM 5.8 CVE-2014-0671 Open redirect vulnerability in Cisco MediaSense allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an … Mediasense Mitigation only Fix from $1,6002014-01-22 MEDIUM 5.0 CVE-2014-0669 The Wireless Session Protocol (WSP) feature in the Gateway GPRS Support Node (GGSN) component on Cisco ASR 5000 series devices allows remote attacker… Asr 5000 Series Software Mitigation only Fix from $1,6002014-01-22 MEDIUM 6.3 CVE-2014-0667 The RMI interface in Cisco Secure Access Control System (ACS) does not properly enforce authorization requirements, which allows remote authenticated… Secure Access Control System Mitigation only Fix from $1,6002014-01-16 MEDIUM 6.8 CVE-2014-0664 The server in Cisco Unity Connection allows remote authenticated users to cause a denial of service (CPU consumption) via unspecified IMAP commands, … Unity Connection Mitigation only Fix from $1,6002014-01-10 MEDIUM 5.4 CVE-2014-0658 Cisco 9900 Unified IP phones allow remote attackers to cause a denial of service (unregistration) via a crafted SIP header, aka Bug ID CSCul24898. Unified Ip Phones 9900 Series Firmware Mitigation only Fix from $1,6002014-01-10 MEDIUM 6.5 CVE-2013-6983 SQL injection vulnerability in the web interface in Cisco Unified Presence Server allows remote authenticated users to execute arbitrary SQL commands… Unified Presence Server Mitigation only Fix from $1,6002013-12-31 MEDIUM 5.4 CVE-2013-6979 The VTY authentication implementation in Cisco IOS XE 03.02.xxSE and 03.03.xxSE incorrectly relies on the Linux-IOS internal-network configuration, w… Ios Xe Mitigation only Fix from $1,6002013-12-23 MEDIUM 6.8 CVE-2013-6976 Cross-site request forgery (CSRF) vulnerability in goform/Quick_setup on Cisco EPC3925 devices allows remote attackers to hijack the authentication o… Epc3925 No fix yet Fix from $1,6002013-12-19 MEDIUM 5.0 CVE-2013-6701 The tNetTaskLimit process on the Transport Node Controller (TNC) on Cisco ONS 15454 devices with software 9.6 and earlier does not properly prioritiz… Cisco Ons 15454 System Software Mitigation only Fix from $1,6002013-12-18 MEDIUM 5.8 CVE-2013-6966 Open redirect vulnerability in Cisco WebEx Training Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing atta… Webex Training Center Mitigation only Fix from $1,6002013-12-17 MEDIUM 6.8 CVE-2013-6710 Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Training Center allows remote attackers to hijack the authentication of unspecified vi… Webex Training Center Mitigation only Fix from $1,6002013-12-14 MEDIUM 5.8 CVE-2013-6959 Open redirect vulnerability in Cisco WebEx Sales Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks… Webex Sales Center Mitigation only Fix from $1,6002013-12-14 MEDIUM 5.8 CVE-2013-6967 Open redirect vulnerability in the mobile-browser subsystem in Cisco WebEx Sales Center allows remote attackers to redirect users to arbitrary web si… Webex Sales Center No fix yet Fix from $1,6002013-12-14 MEDIUM 5.8 CVE-2013-6971 Open redirect vulnerability in Cisco WebEx Training Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing atta… Webex Training Center Mitigation only Fix from $1,6002013-12-14 MEDIUM 5.0 CVE-2013-6965 The registration component in Cisco WebEx Training Center provides the training-session URL before e-mail confirmation is completed, which allows rem… Webex Training Center Mitigation only Fix from $1,6002013-12-14 MEDIUM 5.0 CVE-2013-6968 Cisco WebEx Training Center provides different error messages for registration attempts depending on whether the e-mail address exists, which allows … Webex Training Center Mitigation only Fix from $1,6002013-12-14