Vulnerability index

Browse CVEs

5,759 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firesight System Software MEDIUM 6.8
CVE-2015-6357

The rule-update feature in Cisco FireSIGHT Management Center (MC) 5.2 through 5.4.0.1 does not verify the X.509 certificate of the support.sourcefire…

No fix yet
Fix from $1,600 2015-11-18
Prime Collaboration Assurance MEDIUM 6.8
CVE-2015-6330

Cross-site request forgery (CSRF) vulnerability in Cisco Prime Collaboration Assurance 10.5(1) and 10.6 allows remote attackers to hijack the authent…

Mitigation only
Fix from $1,600 2015-11-18
Aironet Access Point Software HIGH 7.8
CVE-2015-6367

Cisco Aironet 1800 devices with software 8.1(131.0) allow remote attackers to cause a denial of service (CPU consumption) by improperly establishing …

Mitigation only
Fix from $1,950 2015-11-14
Videoscape Distribution Suite Service Manager MEDIUM 5.0
CVE-2015-6364

Cisco Content Delivery System Manager Software 3.2 on Videoscape Distribution Suite Service Manager allows remote attackers to obtain sensitive infor…

Fix: after 3.2.0
Fix from $1,600 2015-11-14
iOS MEDIUM 5.0
CVE-2015-6366

Cisco IOS 15.2(04)M6 and 15.4(03)S lets physical-interface ACLs supersede tunnel-interface ACLs, which allows remote attackers to bypass intended net…

Mitigation only
Fix from $1,600 2015-11-13
Mobility Services Engine MEDIUM 6.5
CVE-2015-6316

The default configuration of sshd_config in Cisco Mobility Services Engine (MSE) through 8.0.120.7 allows logins by the oracle account, which makes i…

Mitigation only
Fix from $1,600 2015-11-06
Web Security Appliance HIGH 9.0
CVE-2015-6298

The admin web interface in Cisco AsyncOS 8.x before 8.0.8-113, 8.1.x and 8.5.x before 8.5.3-051, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.8.x befor…

Mitigation only
Fix from $1,950 2015-11-06
Web Security Appliance HIGH 7.8
CVE-2015-6292

The proxy-cache implementation in Cisco AsyncOS 8.0.x before 8.0.7-151, 8.1.x and 8.5.x before 8.5.2-004, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.…

Mitigation only
Fix from $1,950 2015-11-06
Mobility Services Engine MEDIUM 6.9
CVE-2015-4282

Cisco Mobility Services Engine (MSE) through 8.0.120.7 uses weak permissions for unspecified binary files, which allows local users to obtain root pr…

Mitigation only
Fix from $1,600 2015-11-06
Web Security Appliance HIGH 7.8
CVE-2015-6321

Cisco AsyncOS before 8.5.7-042, 9.x before 9.1.0-032, 9.1.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-042 on Email Security Appliance (ESA) …

Mitigation only
Fix from $1,950 2015-11-06
Web Security Appliance HIGH 7.8
CVE-2015-6293

Cisco AsyncOS 8.x before 8.0.8-113, 8.1.x and 8.5.x before 8.5.3-051, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.8.x before 8.8.0-085 on Web Security…

Mitigation only
Fix from $1,950 2015-11-06
Email Security Appliance HIGH 7.8
CVE-2015-6291

Cisco AsyncOS before 8.5.7-043, 9.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-046 on Email Security Appliance (ESA) devices mishandles malfo…

Mitigation only
Fix from $1,950 2015-11-06
Unified Computing System MEDIUM 5.0
CVE-2015-6355

The web interface in Cisco Unified Computing System (UCS) 2.2(5b)A on blade servers allows remote attackers to obtain potentially sensitive version i…

Mitigation only
Fix from $1,600 2015-11-04
iOS MEDIUM 5.0
CVE-2015-6343

The SIP implementation in Cisco IOS 15.5(3)M on Cisco Unified Border Element (CUBE) devices allows remote attackers to cause a denial of service via …

Mitigation only
Fix from $1,600 2015-10-31
Asr 5000 Software MEDIUM 5.0
CVE-2015-6351

Cisco ASR 5500 System Architecture Evolution (SAE) Gateway devices with software 19.1.0.61559 and 19.2.0 allow remote attackers to cause a denial of …

Mitigation only
Fix from $1,600 2015-10-30
Prime Service Catalog MEDIUM 6.5
CVE-2015-6350

SQL injection vulnerability in the web framework in Cisco Prime Service Catalog 11.0 allows remote authenticated users to execute arbitrary SQL comma…

No fix yet
Fix from $1,600 2015-10-30
Secure Access Control Server MEDIUM 6.5
CVE-2015-6345

SQL injection vulnerability in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to execute…

Mitigation only
Fix from $1,600 2015-10-30
Asr 5000 Software MEDIUM 5.0
CVE-2015-6340

The Proxy Mobile IPv6 (PMIPv6) component in the CDMA implementation on Cisco ASR 5000 devices with software 19.0.M0.60737 allows remote attackers to …

Mitigation only
Fix from $1,600 2015-10-27
Wireless Lan Controller Software MEDIUM 5.0
CVE-2015-6341

The Web Management GUI on Cisco Wireless LAN Controller (WLC) devices with software 7.4(140.0) and 8.0(120.0) allows remote attackers to cause a deni…

Mitigation only
Fix from $1,600 2015-10-25
Firesight System Software HIGH 9.0
CVE-2015-6335

The policy implementation in Cisco FireSIGHT Management Center 5.3.1.7, 5.4.0.4, and 6.0.0 for VMware allows remote authenticated administrators to b…

Mitigation only
Fix from $1,950 2015-10-25
Adaptive Security Appliance Software HIGH 7.8
CVE-2015-6327

The IKEv1 implementation in Cisco Adaptive Security Appliance (ASA) software 7.2 and 8.2 before 8.2(5.58), 8.3 and 8.4 before 8.4(7.29), 8.5 through …

Mitigation only
Fix from $1,950 2015-10-25
Adaptive Security Appliance Software HIGH 7.8
CVE-2015-6326

Cisco Adaptive Security Appliance (ASA) software 7.2 and 8.2 before 8.2(5.58), 8.3 and 8.4 before 8.4(7.29), 8.5 through 8.7 before 8.7(1.17), 9.0 be…

Mitigation only
Fix from $1,950 2015-10-25
Adaptive Security Appliance Software HIGH 7.1
CVE-2015-6325

Cisco Adaptive Security Appliance (ASA) software 7.2 and 8.2 before 8.2(5.58), 8.3 and 8.4 before 8.4(7.29), 8.5 through 8.7 before 8.7(1.17), 9.0 be…

Mitigation only
Fix from $1,950 2015-10-25
Adaptive Security Appliance Software HIGH 7.1
CVE-2015-6324

The DHCPv6 relay implementation in Cisco Adaptive Security Appliance (ASA) software 9.0 before 9.0(4.37), 9.1 before 9.1(6.6), 9.2 before 9.2(4), 9.3…

Mitigation only
Fix from $1,950 2015-10-25
Asr 5000 Software MEDIUM 5.0
CVE-2015-6334

Cisco ASR 5000 and 5500 devices with software 18.0.0.57828 and 19.0.M0.61045 allow remote attackers to cause a denial of service (vpnmgr process rest…

Mitigation only
Fix from $1,600 2015-10-16
Prime Infrastructure MEDIUM 5.0
CVE-2015-6332

Cisco Prime Infrastructure 2.2 allows remote attackers to cause a denial of service (daemon hang) by sending many SSL renegotiation requests, aka Bug…

Mitigation only
Fix from $1,600 2015-10-13
Prime Collaboration Assurance MEDIUM 6.8
CVE-2015-6328

The web framework in Cisco Prime Collaboration Assurance (PCA) 10.5(1) allows remote authenticated users to bypass intended access restrictions and r…

Mitigation only
Fix from $1,600 2015-10-13
Aironet Access Point Software HIGH 7.2
CVE-2015-6315

Cisco Aironet 1850 access points with software 8.1(112.4) allow local users to gain privileges via crafted CLI commands, aka Bug ID CSCuv79694.

Mitigation only
Fix from $1,950 2015-10-13
Prime Collaboration Assurance MEDIUM 6.5
CVE-2015-6331

SQL injection vulnerability in the web framework in Cisco Prime Collaboration Assurance 10.5(1) allows remote authenticated users to execute arbitrar…

Mitigation only
Fix from $1,600 2015-10-12
Prime Collaboration Provisioning MEDIUM 6.5
CVE-2015-6329

SQL injection vulnerability in Cisco Prime Collaboration Provisioning 10.6 and 11.0 allows remote authenticated users to execute arbitrary SQL comman…

Mitigation only
Fix from $1,600 2015-10-12