Vulnerability index

Browse CVEs

5,759 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

iOS HIGH 7.8
CVE-2014-2112

The SSL VPN (aka WebVPN) feature in Cisco IOS 15.1 through 15.4 allows remote attackers to cause a denial of service (memory consumption) via crafted…

Mitigation only
Fix from $1,950 2014-03-27
iOS HIGH 7.8
CVE-2014-2113

Cisco IOS 15.1 through 15.3 and IOS XE 3.3 and 3.5 before 3.5.2E; 3.7 before 3.7.5S; and 3.8, 3.9, and 3.10 before 3.10.2S allow remote attackers to …

Mitigation only
Fix from $1,950 2014-03-27
iOS HIGH 7.1
CVE-2014-2111

The Application Layer Gateway (ALG) module in Cisco IOS 12.2 through 12.4 and 15.0 through 15.4, when NAT is used, allows remote attackers to cause a…

Mitigation only
Fix from $1,950 2014-03-27
iOS HIGH 7.8
CVE-2014-2106

Cisco IOS 15.3M before 15.3(3)M2 and IOS XE 3.10.xS before 3.10.2S allow remote attackers to cause a denial of service (device reload) via crafted SI…

Mitigation only
Fix from $1,950 2014-03-27
iOS HIGH 7.1
CVE-2014-2107

Cisco IOS 12.2 and 15.0 through 15.3, when used with the Kailash FPGA before 2.6 on RSP720-3C-10GE and RSP720-3CXL-10GE devices, allows remote attack…

Mitigation only
Fix from $1,950 2014-03-27
Ironport Asyncos HIGH 8.5
CVE-2014-2119

The End User Safelist/Blocklist (aka SLBL) service in Cisco AsyncOS Software for Email Security Appliance (ESA) before 7.6.3-023 and 8.x before 8.0.1…

Fix: after 7.9.1-039
Fix from $1,950 2014-03-21
iOS HIGH 7.1
CVE-2014-2124

Cisco IOS 15.1(2)SY3 and earlier, when used with Supervisor Engine 2T (aka Sup2T) on Catalyst 6500 devices, allows remote attackers to cause a denial…

Fix: after 15.1
Fix from $1,950 2014-03-21
Webex Meeting Center MEDIUM 5.0
CVE-2014-0708

WebEx Meeting Center in Cisco WebEx Business Suite does not properly compose URLs for HTTP GET requests, which allows remote attackers to obtain sens…

Mitigation only
Fix from $1,600 2014-03-21
Adaptive Security Appliance Software MEDIUM 6.1
CVE-2014-2120 KEVEPSS 19%

Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inje…

Mitigation only
Fix from $1,600 2014-03-19
Hosted Collaboration Solution MEDIUM 5.0
CVE-2014-2121

The Java-based software in Cisco Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (closing of TCP ports) via …

No fix yet
Fix from $1,600 2014-03-19
Hosted Collaboration Solution MEDIUM 5.0
CVE-2014-2122

Memory leak in the GUI in the Impact server in Cisco Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (memory…

Mitigation only
Fix from $1,600 2014-03-19
Cloud Portal MEDIUM 5.0
CVE-2014-0694

Intelligent Automation for Cloud (IAC) in Cisco Cloud Portal 9.4.1 and earlier includes a cryptographic key in binary files, which makes it easier fo…

Fix: after 9.4.1
Fix from $1,600 2014-03-14
Rv110w Firmware HIGH 10.0
CVE-2014-0683EPSS 10%

The web management interface on the Cisco RV110W firewall with firmware 1.2.0.9 and earlier, RV215W router with firmware 1.1.0.5 and earlier, and CVR…

Fix: after 1.2.0.9
Fix from $1,950 2014-03-06
Wireless Lan Controller Software HIGH 10.0
CVE-2014-0703

Cisco Wireless LAN Controller (WLC) devices 7.4 before 7.4.110.0 distribute Aironet IOS software with a race condition in the status of the administr…

Mitigation only
Fix from $1,950 2014-03-06
Wireless Lan Controller Software HIGH 7.8
CVE-2014-0701

Cisco Wireless LAN Controller (WLC) devices 7.0 before 7.0.250.0, 7.2, 7.3, and 7.4 before 7.4.110.0 do not properly deallocate memory, which allows …

Mitigation only
Fix from $1,950 2014-03-06
Wireless Lan Controller Software HIGH 7.8
CVE-2014-0706

Cisco Wireless LAN Controller (WLC) devices 7.2 before 7.2.115.2, 7.3, and 7.4 before 7.4.110.0 allow remote attackers to cause a denial of service (…

Mitigation only
Fix from $1,950 2014-03-06
Wireless Lan Controller Software HIGH 7.8
CVE-2014-0707

Cisco Wireless LAN Controller (WLC) devices 7.2, 7.3, and 7.4 before 7.4.110.0 allow remote attackers to cause a denial of service (device restart) v…

Mitigation only
Fix from $1,950 2014-03-06
Wireless Lan Controller Software HIGH 7.1
CVE-2014-0704

The IGMP implementation on Cisco Wireless LAN Controller (WLC) devices 4.x, 5.x, 6.x, 7.0 before 7.0.250.0, 7.1, 7.2, and 7.3, when IGMPv3 Snooping i…

Mitigation only
Fix from $1,950 2014-03-06
Wireless Lan Controller Software HIGH 7.1
CVE-2014-0705

The multicast listener discovery (MLD) service on Cisco Wireless LAN Controller (WLC) devices 7.2, 7.3, 7.4 before 7.4.121.0, and 7.5, when MLDv2 Sno…

Mitigation only
Fix from $1,950 2014-03-06
Intrusion Prevention System MEDIUM 6.8
CVE-2014-2103

Cisco Intrusion Prevention System (IPS) Software allows remote attackers to cause a denial of service (MainApp process outage) via malformed SNMP pac…

Mitigation only
Fix from $1,600 2014-02-27
Prime Infrastructure HIGH 9.0
CVE-2014-0679

Cisco Prime Infrastructure 1.2 and 1.3 before 1.3.0.20-2, 1.4 before 1.4.0.45-2, and 2.0 before 2.0.0.0.294-2 allows remote authenticated users to ex…

Mitigation only
Fix from $1,950 2014-02-27
Unified Communications Manager MEDIUM 6.8
CVE-2014-0740

Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) interface in the OS Administration component …

Fix: after 10.0
Fix from $1,600 2014-02-27
Unified Contact Center Express Editor Software MEDIUM 6.8
CVE-2014-0745

Cross-site request forgery (CSRF) vulnerability in the Unified Serviceability subsystem in Cisco Unified Contact Center Express (Unified CCX) allows …

Mitigation only
Fix from $1,600 2014-02-27
Unified Communications Manager MEDIUM 6.8
CVE-2014-0747

The Certificate Authority Proxy Function (CAPF) CLI implementation in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows lo…

Fix: after 10.0
Fix from $1,600 2014-02-27
Unified Communications Manager MEDIUM 6.2
CVE-2014-0741

The certificate-import feature in the Certificate Authority Proxy Function (CAPF) CLI implementation in Cisco Unified Communications Manager (Unified…

Fix: after 10.0
Fix from $1,600 2014-02-27
Unified Communications Manager MEDIUM 6.2
CVE-2014-0742

The Certificate Authority Proxy Function (CAPF) CLI implementation in the CSR management feature in Cisco Unified Communications Manager (Unified CM)…

Fix: after 10.0
Fix from $1,600 2014-02-27
Unified Communications Manager MEDIUM 5.0
CVE-2014-0743

The Certificate Authority Proxy Function (CAPF) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote atta…

Fix: after 10.0
Fix from $1,600 2014-02-27
Unified Sip Phone 3905 HIGH 10.0
CVE-2014-0721

The Cisco Unified SIP Phone 3905 with firmware before 9.4(1) allows remote attackers to obtain root access via a session on the test interface on TCP…

Mitigation only
Fix from $1,950 2014-02-22
Ucs Director HIGH 9.3
CVE-2014-0709

Cisco UCS Director (formerly Cloupia) before 4.0.0.3 has a hardcoded password for the root account, which makes it easier for remote attackers to obt…

Fix: after 4.0.0.2
Fix from $1,950 2014-02-22
Ips Sensor Software HIGH 7.8
CVE-2014-0719

The control-plane access-list implementation in Cisco IPS Software before 7.1(8p2)E4 and 7.2 before 7.2(2)E4 allows remote attackers to cause a denia…

Fix: after 7.1
Fix from $1,950 2014-02-22