Vulnerability index

Browse CVEs

5,759 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cloud Portal MEDIUM 5.0
CVE-2014-3351

Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not properly consider whether a session is a problematic NULL session, which all…

Mitigation only
Fix from $1,600 2014-08-29
iOS MEDIUM 5.4
CVE-2014-3347

Cisco IOS 15.1(4)M2 on Cisco 1800 ISR devices, when the ISDN Basic Rate Interface is enabled, allows remote attackers to cause a denial of service (d…

Mitigation only
Fix from $1,600 2014-08-28
Transport Gateway Installation Software MEDIUM 5.0
CVE-2014-3345

The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) 4.0 does not properly check …

Mitigation only
Fix from $1,600 2014-08-28
Nx Os MEDIUM 5.0
CVE-2014-3341

The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages for invalid requests dependin…

Fix: after 7.0
Fix from $1,600 2014-08-19
Unified Communications Manager HIGH 8.5
CVE-2014-3338

The CTIManager module in Cisco Unified Communications Manager (CM) 10.0(1), when single sign-on is enabled, does not properly validate Kerberos SSO t…

Mitigation only
Fix from $1,950 2014-08-12
Unified Communications Domain Manager MEDIUM 6.5
CVE-2014-3339

Multiple SQL injection vulnerabilities in the administrative web interface in Cisco Unified Communications Manager (CM) and Cisco Unified Presence Se…

Mitigation only
Fix from $1,600 2014-08-12
Unified Communications Domain Manager MEDIUM 6.8
CVE-2014-3337

The SIP implementation in Cisco Unified Communications Manager (CM) 8.6(.2) and earlier allows remote authenticated users to cause a denial of servic…

Fix: after 8.6
Fix from $1,600 2014-08-12
iOS HIGH 7.8
CVE-2014-3327

The EnergyWise module in Cisco IOS 12.2, 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.2.xXO, 3.3.xSG, 3.4.xSG, and 3.5.xE before 3.5.3E allows remote atta…

Mitigation only
Fix from $1,950 2014-08-11
Nx Os MEDIUM 5.0
CVE-2014-3330

Cisco NX-OS 6.1(2)I2(1) on Nexus 9000 switches does not properly process packet-drop policy checks for logged packets, which allows remote attackers …

Mitigation only
Fix from $1,600 2014-08-11
Unity Connection HIGH 9.0
CVE-2014-3333

The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticated users to obtain privileged access by conducting an "HTTP Intercept…

Mitigation only
Fix from $1,950 2014-08-11
Unity Connection MEDIUM 6.5
CVE-2014-3336

SQL injection vulnerability in the web framework in Cisco Unity Connection 9.1(2) and earlier allows remote authenticated users to execute arbitrary …

Mitigation only
Fix from $1,600 2014-08-11
Webex Meetings Server MEDIUM 5.8
CVE-2014-3302

user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenticated encryption, which allow…

Fix: after 1.5
Fix from $1,600 2014-08-01
Webex Meetings Server MEDIUM 5.0
CVE-2014-3304

The OutlookAction Class in Cisco WebEx Meetings Server allows remote attackers to enumerate user accounts by entering crafted URLs and examining the …

Mitigation only
Fix from $1,600 2014-07-28
Webex Meetings Server MEDIUM 6.8
CVE-2014-3305

Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers t…

Fix: after 1.5
Fix from $1,600 2014-07-26
Security Manager MEDIUM 6.5
CVE-2014-3326

SQL injection vulnerability in the web framework in Cisco Security Manager 4.5 and 4.6 allows remote authenticated users to execute arbitrary SQL com…

Mitigation only
Fix from $1,600 2014-07-26
Webex Meetings Server MEDIUM 5.0
CVE-2014-3301

The ProfileAction controller in Cisco WebEx Meetings Server (CWMS) 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by…

Fix: after 1.5
Fix from $1,600 2014-07-26
Unified Presence Server MEDIUM 5.0
CVE-2014-3328

The Intercluster Sync Agent Service in Cisco Unified Presence Server allows remote attackers to cause a denial of service via a TCP SYN flood, aka Bu…

Mitigation only
Fix from $1,600 2014-07-26
Ios Xr MEDIUM 6.1
CVE-2014-3322

Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of IP packets, which allows remote attackers to cause…

Fix: after 4.3.2
Fix from $1,600 2014-07-24
Dpc3010 HIGH 10.0
CVE-2014-3306EPSS 7%

The web server on Cisco DPC3010, DPC3212, DPC3825, DPC3925, DPQ3925, EPC3010, EPC3212, EPC3825, and EPC3925 Wireless Residential Gateway products all…

Mitigation only
Fix from $1,950 2014-07-18
Unified Communications Domain Manager MEDIUM 5.8
CVE-2014-3320

Multiple open redirect vulnerabilities in the admin web interface in the web framework in Cisco Unified Communications Domain Manager (CDM) 8.1(.4) a…

Fix: after 8.1
Fix from $1,600 2014-07-18
Ios Xr MEDIUM 5.7
CVE-2014-3321

Cisco IOS XR 4.3.4 and earlier on ASR 9000 devices, when bridge-group virtual interface (BVI) routing is enabled, allows remote attackers to cause a …

Fix: after 4.3.4
Fix from $1,600 2014-07-18
Adaptive Security Appliance Software MEDIUM 6.8
CVE-2013-6691

The WebVPN CIFS implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0(.4.1) and earlier allows remote CIFS servers to cause a denial…

Fix: after 9.0
Fix from $1,600 2014-07-14
Unified Communications Manager MEDIUM 6.8
CVE-2014-3319

Directory traversal vulnerability in the Real-Time Monitoring Tool (RTMT) in Cisco Unified Communications Manager (CM) 10.0(1) allows remote authenti…

Mitigation only
Fix from $1,600 2014-07-14
Unified Communications Manager MEDIUM 5.5
CVE-2014-3317

Directory traversal vulnerability in the Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager 10.0…

Mitigation only
Fix from $1,600 2014-07-14
Adaptive Security Appliance Software MEDIUM 5.4
CVE-2013-5567

Cisco Adaptive Security Appliance (ASA) Software 8.4(.6) and earlier, when using an unsupported configuration with overlapping criteria for filtering…

Fix: after 8.4
Fix from $1,600 2014-07-14
Webex Meeting Center MEDIUM 5.1
CVE-2014-3311

Heap-based buffer overflow in the file-sharing feature in WebEx Meetings Client in Cisco WebEx Meetings Server and WebEx Meeting Center allows remote…

Mitigation only
Fix from $1,600 2014-07-10
Spa 301 1 Line Ip Phone MEDIUM 6.9
CVE-2014-3312

The debug console interface on Cisco Small Business SPA300 and SPA500 phones does not properly perform authentication, which allows local users to ex…

Mitigation only
Fix from $1,600 2014-07-09
iOS MEDIUM 5.0
CVE-2014-3309

The NTP implementation in Cisco IOS and IOS XE does not properly support use of the access-group command for a "deny all" configuration, which allows…

Mitigation only
Fix from $1,600 2014-07-09
Unified Cdm Application Software HIGH 7.5
CVE-2014-3300EPSS 22%

The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 10 does not p…

Fix: after 8.1.4
Fix from $1,950 2014-07-07
Ios Xr MEDIUM 6.4
CVE-2014-3308

Cisco IOS XR on Trident line cards in ASR 9000 devices lacks a static punt policer, which allows remote attackers to cause a denial of service (CPU c…

Mitigation only
Fix from $1,600 2014-07-07