Vulnerability index

Browse CVEs

5,759 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unified Communications Manager MEDIUM 6.9
CVE-2013-6689

Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier allows local users to bypass file permissions, and read, modify, or create arbit…

Fix: after 9.1
Fix from $1,600 2013-11-18
Nexus 1000v MEDIUM 6.8
CVE-2013-5556

The license-installation module on the Cisco Nexus 1000V switch 4.2(1)SV1(5.2b) and earlier for VMware vSphere, Cisco Nexus 1000V switch 5.2(1)SM1(5.…

Fix: after 4.2
Fix from $1,600 2013-11-18
iOS MEDIUM 6.8
CVE-2013-6686

The SSL VPN implementation in Cisco IOS 15.3(1)T2 and earlier allows remote authenticated users to cause a denial of service (interface queue wedge) …

Fix: after 15.3
Fix from $1,600 2013-11-18
Unified Communications Manager MEDIUM 6.3
CVE-2013-6688

Directory traversal vulnerability in the license-upload interface in the Enterprise License Manager (ELM) component in Cisco Unified Communications M…

Fix: after 9.1
Fix from $1,600 2013-11-18
Service Portal MEDIUM 6.8
CVE-2013-3406

The "Files Available for Download" implementation in the Cisco Intelligent Automation for Cloud component in Cisco Services Portal 9.4(1) allows remo…

Mitigation only
Fix from $1,600 2013-11-18
Server Provisioner MEDIUM 5.0
CVE-2013-3407

The web interface in Cisco Server Provisioner 6.4.0 Patch 5-1301292331 and earlier does not require authentication for unspecified pages, which allow…

Fix: after 6.4.0
Fix from $1,600 2013-11-18
Wireless Lan Controller MEDIUM 6.8
CVE-2013-6684

The web framework on Cisco Wireless LAN Controller (WLC) devices does not properly validate configuration parameters, which allows remote authenticat…

Mitigation only
Fix from $1,600 2013-11-13
Unified Ip Phone Firmware MEDIUM 6.6
CVE-2013-6685

The firmware on Cisco Unified IP phones 8961, 9951, and 9971 uses weak permissions for memory block devices, which allows local users to gain privile…

Mitigation only
Fix from $1,600 2013-11-13
Adaptive Security Appliance Software MEDIUM 6.4
CVE-2013-6682

The phone-proxy implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier does not properly validate X.509 certificates,…

Fix: after 9.0.3
Fix from $1,600 2013-11-13
Nx Os MEDIUM 6.1
CVE-2013-6683

The IPv6 implementation in Cisco NX-OS does not properly handle neighbor-table adjacencies, which allows remote attackers to cause a denial of servic…

Mitigation only
Fix from $1,600 2013-11-13
Adaptive Security Appliance Software HIGH 7.1
CVE-2013-5568

The auto-update implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier allows remote attackers to cause a denial of s…

Fix: after 9.0.3
Fix from $1,950 2013-11-13
iOS MEDIUM 6.4
CVE-2013-5552

Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows…

Fix: after 12.4
Fix from $1,600 2013-11-13
Adaptive Security Appliance Software MEDIUM 5.4
CVE-2013-5560

The IPv6 implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1.3 and earlier, when NAT64 or NAT66 is enabled, does not properly proc…

Fix: after 9.1
Fix from $1,600 2013-11-13
Telepresence Vx Clinical Assistant HIGH 10.0
CVE-2013-5558

The WIL-A module in Cisco TelePresence VX Clinical Assistant 1.2 before 1.21 changes the admin password to an empty password upon a reboot, which mak…

Mitigation only
Fix from $1,950 2013-11-08
iOS HIGH 7.8
CVE-2013-5553

Multiple memory leaks in Cisco IOS 15.1 before 15.1(4)M7 allow remote attackers to cause a denial of service (memory consumption or device reload) by…

Mitigation only
Fix from $1,950 2013-11-08
Wide Area Application Services Mobile HIGH 7.5
CVE-2013-5554

Directory traversal vulnerability in the web-management interface in the server in Cisco Wide Area Application Services (WAAS) Mobile before 3.5.5 al…

Fix: after 3.5.4
Fix from $1,950 2013-11-08
Nx Os MEDIUM 5.0
CVE-2013-5566

Cisco NX-OS 5.0 and earlier on MDS 9000 devices allows remote attackers to cause a denial of service (supervisor CPU consumption) via Authentication …

Fix: after 5.0
Fix from $1,600 2013-11-08
Prime Central For Hosted Collaboration Solution MEDIUM 5.0
CVE-2013-5562

The ITM web server in Cisco Prime Central for Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (temporary HTT…

Mitigation only
Fix from $1,600 2013-11-06
Anyconnect Secure Mobility Client MEDIUM 6.8
CVE-2013-5559

Buffer overflow in the Active Template Library (ATL) framework in the VPNAPI COM module in Cisco AnyConnect Secure Mobility Client 2.x allows user-as…

Mitigation only
Fix from $1,600 2013-11-04
Adaptive Security Appliance Cx Context Aware Security Software MEDIUM 5.0
CVE-2013-5561

The Safe Search enforcement feature in Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security Software does not properly perform filtering…

Mitigation only
Fix from $1,600 2013-11-04
Prime Central For Hosted Collaboration Solution MEDIUM 5.0
CVE-2013-5564

The Java process in the Impact server in Cisco Prime Central for Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of ser…

Mitigation only
Fix from $1,600 2013-11-04
Adaptive Security Appliance Software MEDIUM 6.3
CVE-2013-5551

Cisco Adaptive Security Appliance (ASA) Software, when certain same-security-traffic and management-access options are enabled, allows remote authent…

Mitigation only
Fix from $1,600 2013-11-01
Ios Xe HIGH 7.8
CVE-2013-5543

Cisco IOS XE 3.4 before 3.4.2S and 3.5 before 3.5.1S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) via mal…

Mitigation only
Fix from $1,950 2013-10-31
Ios Xe HIGH 7.8
CVE-2013-5545

The PPTP ALG implementation in Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload…

Mitigation only
Fix from $1,950 2013-10-31
Ios Xe HIGH 7.8
CVE-2013-5546

The TCP reassembly feature in Cisco IOS XE 3.7 before 3.7.3S and 3.8 before 3.8.1S on 1000 ASR devices allows remote attackers to cause a denial of s…

Mitigation only
Fix from $1,950 2013-10-31
Ios Xe HIGH 7.8
CVE-2013-5547

Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) by sending malformed EoGRE pa…

Mitigation only
Fix from $1,950 2013-10-31
Ios Xr HIGH 7.1
CVE-2013-5549

Cisco IOS XR 3.8.1 through 4.2.0 does not properly process fragmented packets within the RP-A, RP-B, PRP, and DRP-B route-processor components, which…

Mitigation only
Fix from $1,950 2013-10-25
Identity Services Engine Software MEDIUM 5.0
CVE-2013-5531

Cisco Identity Services Engine (ISE) 1.x before 1.1.1 allows remote attackers to bypass authentication, and read support-bundle configuration and cre…

Mitigation only
Fix from $1,600 2013-10-25
Identity Services Engine Software HIGH 9.0
CVE-2013-5530

The web framework in Cisco Identity Services Engine (ISE) 1.0 and 1.1.0 before 1.1.0.665-5, 1.1.1 before 1.1.1.268-7, 1.1.2 before 1.1.2.145-10, 1.1.…

Mitigation only
Fix from $1,950 2013-10-25
iOS MEDIUM 6.8
CVE-2013-5522

Cisco IOS on Catalyst 3750X switches has default Service Module credentials, which makes it easier for local users to gain privileges via a Service M…

Mitigation only
Fix from $1,600 2013-10-25