Vulnerability index

Browse CVEs

5,759 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Carrier Routing System MEDIUM 5.3
CVE-2016-6401

Cisco Carrier Routing System (CRS) 5.1 and 5.1.4, as used in CRS Carrier Grade Services for CRS-1 and CRS-3 devices, allows remote attackers to cause…

Mitigation only
Fix from $1,600 2016-09-17
Ace Application Control Engine Module A1 HIGH 7.5
CVE-2016-6399

Cisco ACE30 Application Control Engine Module through A5 3.3 and ACE 4700 Application Control Engine appliances through A5 3.3 allow remote attackers…

Mitigation only
Fix from $1,950 2016-09-12
iOS MEDIUM 5.3
CVE-2016-6398

The PPTP server in Cisco IOS 15.5(3)M does not properly initialize packet buffers, which allows remote attackers to obtain sensitive information from…

Mitigation only
Fix from $1,600 2016-09-12
Firesight System Software MEDIUM 5.3
CVE-2016-6396

Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1, when certain malware blocking options are enabled, allow remot…

Mitigation only
Fix from $1,600 2016-09-12
Firesight System Software MEDIUM 5.4
CVE-2016-6395

Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Firepower Management Center before 6.1 and FireSIGHT System S…

Mitigation only
Fix from $1,600 2016-09-12
Firesight System Software CRITICAL 9.1
CVE-2016-6394

Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hija…

Mitigation only
Fix from $2,300 2016-09-12
Hosted Collaboration Mediation Fulfillment HIGH 7.5
CVE-2016-6371

Directory traversal vulnerability in the web interface in Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) 10.6(3) and earlier allows remote …

Mitigation only
Fix from $1,950 2016-09-12
Wireless Lan Controller Software MEDIUM 5.3
CVE-2016-6375

Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow remote attackers to …

Mitigation only
Fix from $1,600 2016-09-12
Spa300 Firmware HIGH 7.5
CVE-2016-1469

The HTTP framework on Cisco SPA300, SPA500, and SPA51x devices allows remote attackers to cause a denial of service (device outage) via a series of m…

Fix: after 7.5.7
Fix from $1,950 2016-09-12
Media Origination System Suite HIGH 8.1
CVE-2016-6377

Media Origination System Suite Software 2.6 and earlier in Cisco Virtual Media Packager (VMP) allows remote attackers to bypass authentication and ma…

Mitigation only
Fix from $1,950 2016-09-03
Webex Wrf Player T29 HIGH 7.8
CVE-2016-1464EPSS 10%

Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to execute arbitrary code via a crafted file, aka Bug I…

No fix yet
Fix from $1,950 2016-09-03
Webex Wrf Player T29 MEDIUM 5.5
CVE-2016-1415EPSS 6%

Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to cause a denial of service (application crash) via a …

No fix yet
Fix from $1,600 2016-09-03
Wireless Lan Controller MEDIUM 6.5
CVE-2016-6376

The Adaptive Wireless Intrusion Prevention System (wIPS) feature on Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x bef…

Mitigation only
Fix from $1,600 2016-09-02
Small Business 220 Series Smart Plus Switches CRITICAL 9.8
CVE-2016-1473

Cisco Small Business 220 devices with firmware before 1.0.1.1 have a hardcoded SNMP community, which allows remote attackers to read or modify SNMP o…

Mitigation only
Fix from $2,300 2016-09-02
Small Business 220 Series Smart Plus Switches HIGH 7.5
CVE-2016-1472

The web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to cause a denial of serv…

Mitigation only
Fix from $1,950 2016-09-02
Small Business 220 Series Smart Plus Switches MEDIUM 6.1
CVE-2016-1471

Cross-site scripting (XSS) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allow…

No fix yet
Fix from $1,600 2016-09-02
Small Business 220 Series Smart Plus Switches HIGH 8.8
CVE-2016-1470

Cross-site request forgery (CSRF) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.…

No fix yet
Fix from $1,950 2016-09-02
Anyconnect Secure Mobility Client HIGH 7.8
CVE-2016-6369

Cisco AnyConnect Secure Mobility Client before 4.2.05015 and 4.3.x before 4.3.02039 mishandles pathnames, which allows local users to gain privileges…

Mitigation only
Fix from $1,950 2016-08-25
Secure Firewall Management Center MEDIUM 6.1
CVE-2016-6365

Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, 5.3.0.2, 5.3.1, and 5.4.0 allows remote attackers…

Mitigation only
Fix from $1,600 2016-08-23
Ios Xr HIGH 7.5
CVE-2016-6355

Memory leak in Cisco IOS XR 5.1.x through 5.1.3, 5.2.x through 5.2.5, and 5.3.x through 5.3.2 on ASR 9001 devices allows remote attackers to cause a …

Mitigation only
Fix from $1,950 2016-08-23
Unified Communications Manager HIGH 7.5
CVE-2016-6364

The User Data Services (UDS) API implementation in Cisco Unified Communications Manager 11.5 allows remote attackers to bypass intended access restri…

Mitigation only
Fix from $1,950 2016-08-23
Webex Meetings Server HIGH 7.5
CVE-2016-1484

Cisco WebEx Meetings Server 2.6 allows remote attackers to bypass intended access restrictions and obtain sensitive application information via unspe…

Mitigation only
Fix from $1,950 2016-08-23
Connected Streaming Analytics MEDIUM 6.5
CVE-2016-1477

Cisco Connected Streaming Analytics 1.1.1 allows remote authenticated users to discover a notification service password by reading administrative pag…

Mitigation only
Fix from $1,600 2016-08-23
Aironet Access Point Software MEDIUM 6.5
CVE-2016-6363

The rate-limit feature in the 802.11 protocol implementation on Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.121.0 and 8.3.x b…

Mitigation only
Fix from $1,600 2016-08-22
Aironet Access Point Software HIGH 7.8
CVE-2016-6362

Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.110.0, 8.2.12x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow local users to …

Mitigation only
Fix from $1,950 2016-08-22
Aironet Access Point Software MEDIUM 6.5
CVE-2016-6361

The Aggregated MAC Protocol Data Unit (AMPDU) implementation on Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.121.0 and 8.3.x b…

Mitigation only
Fix from $1,600 2016-08-22
Transport Gateway Installation Software MEDIUM 6.1
CVE-2016-6359

Cross-site scripting (XSS) vulnerability in Cisco Transport Gateway Installation Software 4.1(4.0) on Smart Call Home Transport Gateway devices allow…

Mitigation only
Fix from $1,600 2016-08-22
Identity Services Engine Software MEDIUM 6.1
CVE-2016-1485

Cross-site scripting (XSS) vulnerability in Cisco Identity Services Engine 1.3(0.876) allows remote attackers to inject arbitrary web script or HTML …

Mitigation only
Fix from $1,600 2016-08-22
Ip Phone 8800 Series Firmware HIGH 7.5
CVE-2016-1479

Cisco IP Phone 8800 devices with software 11.0(1) allow remote attackers to cause a denial of service (memory corruption) via a crafted HTTP request,…

Mitigation only
Fix from $1,950 2016-08-22
Ip Phone 8800 Series Firmware MEDIUM 5.4
CVE-2016-1476

Cross-site scripting (XSS) vulnerability on Cisco IP Phone 8800 devices with software 11.0 allows remote authenticated users to inject arbitrary web …

Mitigation only
Fix from $1,600 2016-08-22