Vulnerability index

Browse CVEs

5,759 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

iOS HIGH 7.8
CVE-2015-0586

The Network-Based Application Recognition (NBAR) protocol implementation in Cisco IOS 15.3(100)M and earlier on Cisco 2900 Integrated Services Router…

Fix: after 15.3
Fix from $1,950 2015-01-28
Prime Service Catalog HIGH 7.5
CVE-2015-0581

The XML parser in Cisco Prime Service Catalog before 10.1 allows remote authenticated users to read arbitrary files or cause a denial of service (CPU…

Fix: after 10.0
Fix from $1,950 2015-01-28
Unified Communications Manager MEDIUM 6.8
CVE-2014-8008EPSS 8%

Absolute path traversal vulnerability in the Real-Time Monitoring Tool (RTMT) API in Cisco Unified Communications Manager (CUCM) allows remote authen…

Mitigation only
Fix from $1,600 2015-01-22
Webex Meeting Center MEDIUM 5.0
CVE-2015-0590

Cisco WebEx Meeting Center allows remote attackers to activate disabled meeting attributes, and consequently obtain sensitive information, by providi…

Mitigation only
Fix from $1,600 2015-01-17
Unified Communications Domain Manager MEDIUM 5.0
CVE-2015-0591

Cisco Unified Communications Domain Manager (UCDM) 10 allows remote attackers to cause a denial of service (daemon hang and GUI outage) via a flood o…

Mitigation only
Fix from $1,600 2015-01-15
Unified Communications Domain Manager MEDIUM 6.8
CVE-2015-0588

Cross-site request forgery (CSRF) vulnerability in Cisco Unified Communications Domain Manager (UCDM) 10 allows remote attackers to hijack the authen…

Mitigation only
Fix from $1,600 2015-01-15
Webex Meetings Server MEDIUM 5.0
CVE-2014-8034

Cisco WebEx Meetings Server 1.5 presents the same CAPTCHA challenge for each login attempt, which makes it easier for remote attackers to obtain acce…

Mitigation only
Fix from $1,600 2015-01-15
Webex Meeting Center MEDIUM 5.0
CVE-2015-0583

Cisco WebEx Meeting Center does not properly restrict the content of URLs, which allows remote attackers to obtain sensitive information via vectors …

Mitigation only
Fix from $1,600 2015-01-14
Telepresence Video Communication Server MEDIUM 5.0
CVE-2015-0579

Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway allow remote attackers to cause a denial of service (memory and CPU consumpt…

Mitigation only
Fix from $1,600 2015-01-14
Adaptive Security Appliance Software MEDIUM 5.7
CVE-2015-0578

Cisco Adaptive Security Appliance (ASA) Software, when a DHCPv6 relay is configured, allows remote attackers to cause a denial of service (device rel…

Mitigation only
Fix from $1,600 2015-01-14
Anyconnect Secure Mobility Client MEDIUM 5.0
CVE-2014-3314

Cisco AnyConnect on Android and OS X does not properly verify the host type, which allows remote attackers to spoof authentication forms and possibly…

Mitigation only
Fix from $1,600 2015-01-14
Nx Os MEDIUM 5.0
CVE-2015-0582

The High Availability (HA) subsystem in Cisco NX-OS on MDS 9000 devices allows remote attackers to cause a denial of service via crafted traffic, aka…

Mitigation only
Fix from $1,600 2015-01-10
Webex Meetings Server MEDIUM 5.0
CVE-2014-8035

The web framework in Cisco WebEx Meetings Server produces different returned messages for URL requests depending on whether a username exists, which …

Mitigation only
Fix from $1,600 2015-01-10
Webex Meetings Server MEDIUM 5.0
CVE-2014-8036

The outlookpa component in Cisco WebEx Meetings Server does not properly validate API input, which allows remote attackers to modify a meeting's invi…

Mitigation only
Fix from $1,600 2015-01-10
Unified Communications Domain Manager MEDIUM 5.0
CVE-2014-8020

Cisco Unified Communication Domain Manager Platform Software allows remote attackers to cause a denial of service (CPU consumption, and performance d…

Mitigation only
Fix from $1,600 2015-01-10
Webex Meetings Server MEDIUM 5.0
CVE-2014-8033

The play/modules component in Cisco WebEx Meetings Server allows remote attackers to obtain administrator access via crafted API requests, aka Bug ID…

Mitigation only
Fix from $1,600 2015-01-09
Webex Meetings Server MEDIUM 6.8
CVE-2014-8031

Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server allows remote attackers to hijack the authentication of arbitrary user…

Mitigation only
Fix from $1,600 2015-01-09
Secure Access Control System MEDIUM 5.8
CVE-2014-8029

Open redirect vulnerability in the web interface in Cisco Secure Access Control System (ACS) allows remote attackers to redirect users to arbitrary w…

Mitigation only
Fix from $1,600 2015-01-09
Secure Access Control System MEDIUM 6.5
CVE-2014-8027

The RBAC component in Cisco Secure Access Control System (ACS) allows remote authenticated users to obtain Network Device Administrator privileges fo…

Mitigation only
Fix from $1,600 2015-01-09
Meraki Mr Firmware HIGH 7.7
CVE-2014-7999

Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote authenticated users to install arbitrary firmware by leveraging unsp…

Fix: after 2014-09-24
Fix from $1,950 2014-12-24
Meraki Mx Firmware HIGH 7.2
CVE-2014-7995

Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow physically proximate attackers to obtain shell access by opening a device's…

Fix: after 2014-09-24
Fix from $1,950 2014-12-24
Meraki Mr Firmware MEDIUM 5.4
CVE-2014-7994

Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote attackers to execute arbitrary commands by leveraging knowledge of a…

Fix: after 2014-09-24
Fix from $1,600 2014-12-24
Identity Services Engine Software MEDIUM 5.0
CVE-2014-8017

The periodic-backup feature in Cisco Identity Services Engine (ISE) allows remote attackers to discover backup-encryption passwords via a crafted req…

Mitigation only
Fix from $1,600 2014-12-22
Enterprise Content Delivery System MEDIUM 5.0
CVE-2014-8019

Directory traversal vulnerability in Cisco Enterprise Content Delivery System (ECDS) allows remote attackers to read arbitrary files via a crafted UR…

Mitigation only
Fix from $1,600 2014-12-20
Ironport Email Security Appliances MEDIUM 5.0
CVE-2014-8016

The Cisco IronPort Email Security Appliance (ESA) allows remote attackers to cause a denial of service (CPU consumption) via long Subject headers in …

Mitigation only
Fix from $1,600 2014-12-19
Ios Xr MEDIUM 5.0
CVE-2014-8014

Cisco IOS XR allows remote attackers to cause a denial of service (RSVP process reload) via a malformed RSVP packet, aka Bug ID CSCub63710.

Mitigation only
Fix from $1,600 2014-12-18
Unified Communications Domain Manager MEDIUM 6.5
CVE-2014-8010

The web framework in Cisco Unified Communications Domain Manager 8 allows remote authenticated administrators to execute arbitrary OS commands via cr…

Mitigation only
Fix from $1,600 2014-12-10
Unified Computing System MEDIUM 5.0
CVE-2014-8009

The Management subsystem in Cisco Unified Computing System 2.1(3f) and earlier allows remote attackers to obtain sensitive information by reading log…

Fix: after 2.1
Fix from $1,600 2014-12-10
Unified Computing System HIGH 7.2
CVE-2014-8003

Cisco Integrated Management Controller in Cisco Unified Computing System 2.2(2c)A and earlier allows local users to obtain shell access via a crafted…

Fix: after 2.2
Fix from $1,950 2014-12-10
Adaptive Security Appliance Software MEDIUM 5.0
CVE-2014-3407

The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(.2) and earlier does not properly allocate memory blocks during HT…

Fix: after 9.3
Fix from $1,600 2014-11-28