Vulnerability index

Browse CVEs

5,759 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ios Xr MEDIUM 5.0
CVE-2014-8005

Race condition in the lighttpd module in Cisco IOS XR 5.1 and earlier on Network Convergence System 6000 devices allows remote attackers to cause a d…

Fix: after 5.1.0
Fix from $1,600 2014-11-26
Ios Xr MEDIUM 5.0
CVE-2014-8004

Cisco IOS XR allows remote attackers to cause a denial of service (LISP process reload) by establishing many LISP TCP sessions, aka Bug ID CSCuq90378.

Mitigation only
Fix from $1,600 2014-11-25
Openh264 HIGH 7.5
CVE-2014-8002

Use-after-free vulnerability in decode_slice.cpp in Cisco OpenH264 1.2.0 and earlier allows remote attackers to execute arbitrary code via an encoded…

Fix: after 1.2.0
Fix from $1,950 2014-11-25
Openh264 HIGH 7.5
CVE-2014-8001

Buffer overflow in decode.cpp in Cisco OpenH264 1.2.0 and earlier allows remote attackers to execute arbitrary code via an encoded media file.

Fix: after 1.2.0
Fix from $1,950 2014-11-25
Unified Communications Manager Im And Presence Service MEDIUM 5.0
CVE-2014-8000

Cisco Unified Communications Manager IM and Presence Service 9.1(1) produces different returned messages for URL requests depending on whether a user…

Mitigation only
Fix from $1,600 2014-11-21
Unified Computing System MEDIUM 6.8
CVE-2014-7996

Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Integrated Management Controller in Cisco Unified Computing System allo…

Mitigation only
Fix from $1,600 2014-11-18
iOS MEDIUM 5.0
CVE-2014-7992EPSS 27%

The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensitive credential information fro…

Mitigation only
Fix from $1,600 2014-11-18
iOS HIGH 7.1
CVE-2014-7998

Cisco IOS on Aironet access points, when "dot11 aaa authenticator" debugging is enabled, allows remote attackers to cause a denial of service via a m…

Mitigation only
Fix from $1,950 2014-11-15
iOS MEDIUM 6.1
CVE-2014-7997

The DHCP implementation in Cisco IOS on Aironet access points does not properly handle error conditions with short leases and unsuccessful lease-rene…

Mitigation only
Fix from $1,600 2014-11-15
B200 M3 MEDIUM 6.8
CVE-2014-7989

Cisco Unified Computing System on B-Series blade servers allows local users to gain shell privileges via a crafted (1) ping6 or (2) traceroute6 comma…

Mitigation only
Fix from $1,600 2014-11-07
Ios Xe MEDIUM 6.8
CVE-2014-7990

Cisco IOS XE 3.5E and earlier on WS-C3850, WS-C3860, and AIR-CT5760 devices does not properly parse the "request system shell" challenge response, wh…

Fix: after 3.5e
Fix from $1,600 2014-11-07
Rv120w Firmware HIGH 9.0
CVE-2014-2177

The network-diagnostics administration interface in the Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.…

Fix: after 1.0.5.8
Fix from $1,950 2014-11-07
Rv180 Firmware MEDIUM 6.8
CVE-2014-2178

Cross-site request forgery (CSRF) vulnerability in the administrative web interface in the Cisco RV router firmware on RV220W devices, before 1.0.5.9…

Fix: after 1.0.5.8
Fix from $1,600 2014-11-07
Rv180 Firmware MEDIUM 5.0
CVE-2014-2179

The Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote attac…

Fix: after 1.0.5.8
Fix from $1,600 2014-11-07
Unified Communications Manager MEDIUM 6.5
CVE-2014-3366

SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to execute …

Mitigation only
Fix from $1,600 2014-10-31
iOS MEDIUM 5.0
CVE-2014-3293

Cisco IOS 15.4(3)S0b on ASR901 devices makes incorrect decisions to use the CPU for IPv4 packet processing, which allows remote attackers to cause a …

Mitigation only
Fix from $1,600 2014-10-28
iOS MEDIUM 6.1
CVE-2014-3409

The Ethernet Connectivity Fault Management (CFM) handling feature in Cisco IOS 12.2(33)SRE9a and earlier and IOS XE 3.13S and earlier allows remote a…

Fix: after 12.2
Fix from $1,600 2014-10-25
Expressway Software HIGH 7.8
CVE-2014-3368

Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.2 allow remote attackers to cause a denial of service (device r…

Mitigation only
Fix from $1,950 2014-10-19
Telepresence Mcu Software HIGH 7.8
CVE-2014-3397

The network stack in Cisco TelePresence MCU Software before 4.3(2.30) allows remote attackers to cause a denial of service (memory consumption) via c…

Fix: after 4.3
Fix from $1,950 2014-10-19
Expressway Software HIGH 7.1
CVE-2014-3369

The SIP IX implementation in Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allows remote attackers to cau…

Mitigation only
Fix from $1,950 2014-10-19
Telepresence Video Communication Server Software HIGH 7.1
CVE-2014-3370

Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allow remote attackers to cause a denial of service (device…

Mitigation only
Fix from $1,950 2014-10-19
Intrusion Prevention System HIGH 7.1
CVE-2014-3406

Race condition in the IP logging feature in Cisco Intrusion Prevention System (IPS) Software 7.1(7)E4 and earlier allows remote attackers to cause a …

Fix: after 7.1
Fix from $1,950 2014-10-19
Prime Optical MEDIUM 6.8
CVE-2014-3408

Cross-site scripting (XSS) vulnerability in the web framework in Cisco Prime Optical 10 allows remote attackers to inject arbitrary web script or HTM…

Mitigation only
Fix from $1,600 2014-10-19
Asyncos MEDIUM 5.0
CVE-2014-3381

The ZIP inspection engine in Cisco AsyncOS 8.5 and earlier on the Cisco Email Security Appliance (ESA) does not properly analyze ZIP archives, which …

Fix: after 8.5
Fix from $1,600 2014-10-19
Asa HIGH 9.0
CVE-2014-3389

The VPN implementation in Cisco ASA Software 7.2 before 7.2(5.15), 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.6 before 8.6(1…

Mitigation only
Fix from $1,950 2014-10-10
Adaptive Security Appliance Software HIGH 8.3
CVE-2014-3392

The Clientless SSL VPN portal in Cisco ASA Software 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.6 before 8.6(1.15), 9.0 befor…

Mitigation only
Fix from $1,950 2014-10-10
Asa HIGH 7.8
CVE-2014-3382

The SQL*Net inspection engine in Cisco ASA Software 7.2 before 7.2(5.13), 8.2 before 8.2(5.50), 8.3 before 8.3(2.42), 8.4 before 8.4(7.15), 8.5 befor…

Mitigation only
Fix from $1,950 2014-10-10
Asa HIGH 7.8
CVE-2014-3383

The IKE implementation in the VPN component in Cisco ASA Software 9.1 before 9.1(5.1) allows remote attackers to cause a denial of service (device re…

Mitigation only
Fix from $1,950 2014-10-10
Asa HIGH 7.8
CVE-2014-3384

The IKEv2 implementation in Cisco ASA Software 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1) allows remote…

Mitigation only
Fix from $1,950 2014-10-10
Asa HIGH 7.8
CVE-2014-3385

Race condition in the Health and Performance Monitoring (HPM) for ASDM feature in Cisco ASA Software 8.3 before 8.3(2.42), 8.4 before 8.4(7.11), 8.5 …

Mitigation only
Fix from $1,950 2014-10-10