Vulnerability index

Browse CVEs

5,759 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firewall Services Module Software HIGH 7.1
CVE-2014-0710

Race condition in the cut-through proxy feature in Cisco Firewall Services Module (FWSM) Software 3.x before 3.2(28) and 4.x before 4.1(15) allows re…

Mitigation only
Fix from $1,950 2014-02-22
Ips Sensor Software HIGH 7.1
CVE-2014-0718

The produce-verbose-alert feature in Cisco IPS Software 7.1 before 7.1(8)E4 and 7.2 before 7.2(2)E4 allows remote attackers to cause a denial of serv…

Mitigation only
Fix from $1,950 2014-02-22
Ips Sensor Software HIGH 7.1
CVE-2014-0720

Cisco IPS Software 7.1 before 7.1(8)E4 and 7.2 before 7.2(2)E4 allows remote attackers to cause a denial of service (Analysis Engine process outage) …

Fix: after 7.1
Fix from $1,950 2014-02-22
Unified Computing System Central Software MEDIUM 6.8
CVE-2014-0730

Cisco Unified Computing System (UCS) Central Software 1.1 and earlier allows local users to gain privileges via a CLI copy command in a local-mgmt co…

Fix: after 1.1
Fix from $1,600 2014-02-22
Unified Communications Manager MEDIUM 5.0
CVE-2014-0731

The administration interface in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to bypass authenticatio…

Fix: after 10.0
Fix from $1,600 2014-02-22
Unified Communications Manager MEDIUM 5.0
CVE-2014-0733

The Enterprise License Manager (ELM) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce aut…

Fix: after 10.0
Fix from $1,600 2014-02-20
Unified Communications Manager HIGH 7.5
CVE-2014-0734

SQL injection vulnerability in the Certificate Authority Proxy Function (CAPF) implementation in Cisco Unified Communications Manager (Unified CM) 10…

Fix: after 10.0
Fix from $1,950 2014-02-20
Unified Communications Manager MEDIUM 6.8
CVE-2014-0736

Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) page in Cisco Unified Communications Manager …

Fix: after 10.0
Fix from $1,600 2014-02-20
Unified Communications Manager MEDIUM 5.0
CVE-2014-0732

The Real Time Monitoring Tool (RTMT) web application in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enfor…

Fix: after 10.0
Fix from $1,600 2014-02-20
Unified Communications Manager HIGH 7.5
CVE-2014-0726

SQL injection vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows rem…

Fix: after 10.0
Fix from $1,950 2014-02-13
Unified Communications Manager HIGH 7.5
CVE-2014-0727

SQL injection vulnerability in the CallManager Interactive Voice Response (CMIVR) interface in Cisco Unified Communications Manager (UCM) allows remo…

Mitigation only
Fix from $1,950 2014-02-13
Unified Communications Manager HIGH 7.5
CVE-2014-0728

SQL injection vulnerability in the Java database interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers …

Fix: after 10.0
Fix from $1,950 2014-02-13
Unified Communications Manager HIGH 7.5
CVE-2014-0729

SQL injection vulnerability in the Enterprise Mobility Application (EMApp) interface in Cisco Unified Communications Manager (UCM) allows remote atta…

Mitigation only
Fix from $1,950 2014-02-13
Unified Communications Manager MEDIUM 5.0
CVE-2014-0722

The log4jinit web application in Cisco Unified Communications Manager (UCM) does not properly validate authentication, which allows remote attackers …

Mitigation only
Fix from $1,600 2014-02-13
Unified Communications Manager MEDIUM 5.0
CVE-2014-0725

Cisco Unified Communications Manager (UCM) does not require authentication for reading WAR files, which allows remote attackers to obtain sensitive i…

Mitigation only
Fix from $1,600 2014-02-13
Unified Communications Manager MEDIUM 6.0
CVE-2014-0686

Cisco Unified Communications Manager (aka Unified CM) 9.1 (2.10000.28) and earlier allows local users to gain privileges by leveraging incorrect file…

Fix: after 9.1
Fix from $1,600 2014-02-04
Secure Access Control System MEDIUM 5.5
CVE-2014-0678

The portal interface in Cisco Secure Access Control System (ACS) does not properly manage sessions, which allows remote authenticated users to hijack…

Mitigation only
Fix from $1,600 2014-01-25
Video Surveillance Operations Manager MEDIUM 6.8
CVE-2014-0674

Cisco Video Surveillance Operations Manager (VSOM) does not require authentication for MySQL database connections, which allows remote attackers to o…

Mitigation only
Fix from $1,600 2014-01-24
Telepresence Video Communication Server MEDIUM 6.4
CVE-2014-0675

The Expressway component in Cisco TelePresence Video Communication Server (VCS) uses the same default X.509 certificate across different customers' i…

Mitigation only
Fix from $1,600 2014-01-23
Telepresence System Software HIGH 8.3
CVE-2014-0661

The System Status Collection Daemon (SSCD) in Cisco TelePresence System 500-37, 1000, 1300-65, and 3xxx before 1.10.2(42), and 500-32, 1300-47, TX131…

Fix: after 1.10.1
Fix from $1,950 2014-01-22
Telepresence Video Communication Server Software HIGH 7.1
CVE-2014-0662

The SIP module in Cisco TelePresence Video Communication Server (VCS) before 8.1 allows remote attackers to cause a denial of service (process failur…

Mitigation only
Fix from $1,950 2014-01-22
Nx Os MEDIUM 6.8
CVE-2014-0676

Cisco NX-OS allows local users to bypass intended TACACS+ command restrictions via a series of multiple commands, aka Bug ID CSCum47367.

Mitigation only
Fix from $1,600 2014-01-22
Nx Os MEDIUM 5.0
CVE-2014-0677

The Label Distribution Protocol (LDP) functionality in Cisco NX-OS allows remote attackers to cause a denial of service (temporary LDP session outage…

Mitigation only
Fix from $1,600 2014-01-22
Telepresence Isdn Gateway Software HIGH 7.1
CVE-2014-0660

Cisco TelePresence ISDN Gateway with software before 2.2(1.92) allows remote attackers to cause a denial of service (D-channel call outage) via a cra…

Fix: after 2.1
Fix from $1,950 2014-01-22
Mediasense MEDIUM 5.8
CVE-2014-0671

Open redirect vulnerability in Cisco MediaSense allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an …

Mitigation only
Fix from $1,600 2014-01-22
Asr 5000 Series Software MEDIUM 5.0
CVE-2014-0669

The Wireless Session Protocol (WSP) feature in the Gateway GPRS Support Node (GGSN) component on Cisco ASR 5000 series devices allows remote attacker…

Mitigation only
Fix from $1,600 2014-01-22
Secure Access Control System HIGH 10.0
CVE-2014-0648EPSS 6%

The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authentication and authorization requirements,…

Fix: after 5.4.0.46.6
Fix from $1,950 2014-01-16
Secure Access Control System HIGH 10.0
CVE-2014-0650

The web interface in Cisco Secure Access Control System (ACS) 5.x before 5.4 Patch 3 allows remote attackers to execute arbitrary operating-system co…

Fix: after 5.4.0.46.2
Fix from $1,950 2014-01-16
Secure Access Control System HIGH 9.0
CVE-2014-0649

The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authorization requirements, which allows remot…

Fix: after 5.4.0.46.6
Fix from $1,950 2014-01-16
Secure Access Control System MEDIUM 6.3
CVE-2014-0667

The RMI interface in Cisco Secure Access Control System (ACS) does not properly enforce authorization requirements, which allows remote authenticated…

Mitigation only
Fix from $1,600 2014-01-16