Vulnerability index

Browse CVEs

5,759 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firesight System Software HIGH 7.5
CVE-2016-1368

Cisco FirePOWER System Software 5.3.x through 5.3.0.6 and 5.4.x through 5.4.0.3 on FirePOWER 7000 and 8000 appliances, and on the Advanced Malware Pr…

Mitigation only
Fix from $1,950 2016-05-05
Information Server CRITICAL 10.0
CVE-2016-1343

The XML parser in Cisco Information Server (CIS) 6.2 allows remote attackers to read arbitrary files or cause a denial of service (CPU and memory con…

Mitigation only
Fix from $2,300 2016-04-30
Webex Productivity Tools HIGH 7.8
CVE-2016-4349

Untrusted search path vulnerability in Cisco WebEx Productivity Tools 2.40.5001.10012 allows local users to gain privileges via a Trojan horse crypts…

Mitigation only
Fix from $1,950 2016-04-28
Webex Meetings Server HIGH 7.4
CVE-2016-1389

Open redirect vulnerability in Cisco WebEx Meetings Server (CWMS) 2.6 allows remote attackers to redirect users to arbitrary web sites and conduct ph…

Mitigation only
Fix from $1,950 2016-04-28
Application Policy Infrastructure Controller Enterprise Module HIGH 7.5
CVE-2016-1386

The API in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0(1) allows remote attackers to spoof administrative noti…

Mitigation only
Fix from $1,950 2016-04-28
Adaptive Security Appliance Software HIGH 7.5
CVE-2016-1367

The DHCPv6 relay implementation in Cisco Adaptive Security Appliance (ASA) Software 9.4.1 allows remote attackers to cause a denial of service (devic…

Mitigation only
Fix from $1,950 2016-04-21
Wireless Lan Controller Software HIGH 7.5
CVE-2016-1364

Cisco Wireless LAN Controller (WLC) Software 7.4 before 7.4.130.0(MD) and 7.5, 7.6, and 8.0 before 8.0.110.0(ED) allows remote attackers to cause a d…

Mitigation only
Fix from $1,950 2016-04-21
Wireless Lan Controller Software CRITICAL 9.8
CVE-2016-1363EPSS 6%

Buffer overflow in the redirection functionality in Cisco Wireless LAN Controller (WLC) Software 7.2 through 7.4 before 7.4.140.0(MD) and 7.5 through…

Fix: 7.4.140.0 / 8.0.115.0+
Fix from $2,300 2016-04-21
Aireos HIGH 7.5
CVE-2016-1362

Cisco AireOS 4.1 through 7.4.120.0, 7.5.x, and 7.6.100.0 on Wireless LAN Controller (WLC) devices allows remote attackers to cause a denial of servic…

Mitigation only
Fix from $1,950 2016-04-21
Ios Xe HIGH 7.5
CVE-2015-6360EPSS 8%

The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted fields in SRTP packe…

Mitigation only
Fix from $1,950 2016-04-21
iOS HIGH 7.5
CVE-2016-1384

The NTP implementation in Cisco IOS 15.1 and 15.5 and IOS XE 3.2 through 3.17 allows remote attackers to modify the system time via crafted packets, …

Mitigation only
Fix from $1,950 2016-04-20
Unified Computing System Platform Emulator HIGH 8.4
CVE-2016-1340

Heap-based buffer overflow in Cisco Unified Computing System (UCS) Platform Emulator 2.5(2)TS4, 3.0(2c)A, and 3.0(2c)TS9 allows local users to gain p…

Mitigation only
Fix from $1,950 2016-04-16
Unified Computing System Platform Emulator HIGH 7.8
CVE-2016-1339

Cisco Unified Computing System (UCS) Platform Emulator 2.5(2)TS4, 3.0(2c)A, and 3.0(2c)TS9 allows local users to gain privileges via crafted argument…

Mitigation only
Fix from $1,950 2016-04-16
iOS MEDIUM 5.3
CVE-2016-1378

Cisco IOS before 15.2(2)E1 on Catalyst switches allows remote attackers to obtain potentially sensitive software-version information via a request to…

Mitigation only
Fix from $1,600 2016-04-14
Unified Computing System Central Software CRITICAL 9.8
CVE-2016-1352

Cisco Unified Computing System (UCS) Central Software 1.3(1b) and earlier allows remote attackers to execute arbitrary OS commands via a crafted HTTP…

Mitigation only
Fix from $2,300 2016-04-14
Unity Connection MEDIUM 6.1
CVE-2016-1377

Cross-site scripting (XSS) vulnerability in Cisco Unity Connection through 11.0 allows remote attackers to inject arbitrary web script or HTML via un…

No fix yet
Fix from $1,600 2016-04-12
Ios Xr MEDIUM 5.3
CVE-2016-1376

Cisco IOS XR 4.2.3, 4.3.0, 4.3.4, and 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (CRC and symbol errors, and inte…

Mitigation only
Fix from $1,600 2016-04-12
Ip Interoperability And Collaboration System MEDIUM 6.1
CVE-2016-1375

Cross-site scripting (XSS) vulnerability in Cisco IP Interoperability and Collaboration System 4.10(1) allows remote attackers to inject arbitrary we…

Mitigation only
Fix from $1,600 2016-04-08
Ucs Invicta C3124sa Appliance CRITICAL 9.8
CVE-2016-1313

Cisco UCS Invicta C3124SA Appliance 4.3.1 through 5.0.1, UCS Invicta Scaling System and Appliance, and Whiptail Racerunner improperly store a default…

Mitigation only
Fix from $2,300 2016-04-06
Evolved Programmable Network Manager CRITICAL 9.8
CVE-2016-1291EPSS 7%

Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary…

Mitigation only
Fix from $2,300 2016-04-06
Evolved Programmable Network Manager HIGH 8.1
CVE-2016-1290

The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated …

Mitigation only
Fix from $1,950 2016-04-06
Asa With Firepower Services HIGH 7.5
CVE-2016-1345

Cisco FireSIGHT System Software 5.4.0 through 6.0.1 and ASA with FirePOWER Services 5.4.0 through 6.0.0.1 allow remote attackers to bypass malware pr…

Mitigation only
Fix from $1,950 2016-04-01
iOS HIGH 7.5
CVE-2016-1351

The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.1 and 15.2 and NX-OS 4.1 through 6.2 allows remote attackers to cause a deni…

Mitigation only
Fix from $1,950 2016-03-26
Ios Xe HIGH 7.5
CVE-2016-1350

Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager allow remote attackers to cause a denial of service …

Fix: 2.50+
Fix from $1,950 2016-03-26
Ios Xe HIGH 7.5
CVE-2016-1349

The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to cause a denial of ser…

Fix: 2.50 / 2017-01-06+
Fix from $1,950 2016-03-26
Ios Xe HIGH 7.5
CVE-2016-1348

Cisco IOS 15.0 through 15.5 and IOS XE 3.3 through 3.16 allow remote attackers to cause a denial of service (device reload) via a crafted DHCPv6 Rela…

Fix: 2.50 / 2017-01-06+
Fix from $1,950 2016-03-26
Ios Xe MEDIUM 5.9
CVE-2016-1344

The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote attackers to cause a denial of service (device relo…

Fix: 2.50 / 2017-01-06+
Fix from $1,600 2016-03-26
iOS HIGH 7.5
CVE-2016-1347

The Wide Area Application Services (WAAS) Express implementation in Cisco IOS 15.1 through 15.5 allows remote attackers to cause a denial of service …

Mitigation only
Fix from $1,950 2016-03-24
Ios Xr MEDIUM 6.5
CVE-2016-1366

The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devices use weak permissions for system files, which …

Mitigation only
Fix from $1,600 2016-03-24
Ios Xr MEDIUM 5.3
CVE-2016-1361

Cisco IOS XR through 4.3.2 on Gigabit Switch Router (GSR) 12000 devices does not properly check for a Bidirectional Forwarding Detection (BFD) header…

Mitigation only
Fix from $1,600 2016-03-12