Vulnerability index

Browse CVEs

5,759 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unified Computing System MEDIUM 5.0
CVE-2013-1190

The C-Series Rack Server component 1.4 in Cisco Unified Computing System (UCS) does not properly restrict inbound access to ports, which allows remot…

Mitigation only
Fix from $1,600 2013-08-02
Wide Area Application Services HIGH 10.0
CVE-2013-3443EPSS 6%

The web service framework in Cisco WAAS Software 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1 in a Central Manager (CM) con…

Mitigation only
Fix from $1,950 2013-08-01
Wide Area Application Services HIGH 9.0
CVE-2013-3444

The web framework in Cisco WAAS Software before 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1; Cisco ACNS Software 4.x and 5…

Mitigation only
Fix from $1,950 2013-08-01
Vc240 Network Bullet Camera MEDIUM 5.0
CVE-2012-3913

The Cisco VC220 and VC240 cameras allow remote attackers to cause a denial of service (WebUI outage) via crafted packets, aka Bug IDs CSCtf73188, CSC…

Mitigation only
Fix from $1,600 2013-08-01
Identity Services Engine MEDIUM 5.0
CVE-2013-3445

The firewall subsystem in Cisco Identity Services Engine has an incorrect rule for open ports, which allows remote attackers to cause a denial of ser…

Mitigation only
Fix from $1,600 2013-07-29
Video Surveillance Manager HIGH 9.0
CVE-2013-3430EPSS 8%

Cisco Video Surveillance Manager (VSM) before 7.0.0 allows remote attackers to obtain sensitive configuration, archive, and log information via unspe…

Fix: after 6.3.3
Fix from $1,950 2013-07-25
Video Surveillance Manager HIGH 7.8
CVE-2013-3429EPSS 10%

Multiple directory traversal vulnerabilities in Cisco Video Surveillance Manager (VSM) before 7.0.0 allow remote attackers to read system files via a…

Fix: after 6.3.3
Fix from $1,950 2013-07-25
Video Surveillance Manager HIGH 7.8
CVE-2013-3431EPSS 9%

Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages, which allows remote attacker…

Fix: after 6.3.3
Fix from $1,950 2013-07-25
Unified Meetingplace Web Conferencing MEDIUM 5.0
CVE-2013-3438

The web framework in the server in Cisco Unified MeetingPlace Web Conferencing allows remote attackers to bypass intended access restrictions and rea…

No fix yet
Fix from $1,600 2013-07-24
Aironet 3600 MEDIUM 5.4
CVE-2013-3441

Cisco Aironet 3600 access points allow remote attackers to cause a denial of service (memory corruption and device crash) by disrupting Cisco Wireles…

Mitigation only
Fix from $1,600 2013-07-23
Unified Operations Manager MEDIUM 6.5
CVE-2013-3437

SQL injection vulnerability in the management application in Cisco Unified Operations Manager allows remote authenticated users to execute arbitrary …

Mitigation only
Fix from $1,600 2013-07-23
Unified Ip Conference Station 7937g Firmware MEDIUM 5.0
CVE-2013-3435

The Cisco Unified IP Conference Station 7937G allows remote attackers to cause a denial of service (networking outage) via a flood of TCP packets, ak…

Mitigation only
Fix from $1,600 2013-07-23
iOS MEDIUM 5.0
CVE-2013-3436

The default configuration of the Group Encrypted Transport VPN (GET VPN) feature on Cisco IOS uses an improper mechanism for enabling Group Domain of…

Mitigation only
Fix from $1,600 2013-07-19
Identity Services Engine Software MEDIUM 6.8
CVE-2013-3420

Cross-site request forgery (CSRF) vulnerability in the web framework on the Cisco Identity Services Engine (ISE) allows remote attackers to hijack th…

Mitigation only
Fix from $1,600 2013-07-18
Unified Ip Phones 9900 Series Firmware MEDIUM 5.0
CVE-2013-3426

The Serviceability servlet on Cisco 9900 IP phones does not properly restrict paths, which allows remote attackers to read arbitrary files by specify…

Mitigation only
Fix from $1,600 2013-07-18
Asa 5500 X Series Ips Ssp Software HIGH 7.8
CVE-2013-1218

Cisco Intrusion Prevention System (IPS) Software in ASA 5500-X IPS-SSP software modules before 7.1(7)sp1E4 allows remote attackers to cause a denial …

Fix: after 7.1
Fix from $1,950 2013-07-18
Asa 5500 X Series Ips Ssp Software HIGH 7.8
CVE-2013-1243

The IP stack in Cisco Intrusion Prevention System (IPS) Software in ASA 5500-X IPS-SSP software and hardware modules before 7.1(5)E4, IPS 4500 sensor…

Fix: after 7.1
Fix from $1,950 2013-07-18
Intrusion Prevention System HIGH 7.8
CVE-2013-3410

Cisco Intrusion Prevention System (IPS) Software on IPS NME devices before 7.0(9)E4 allows remote attackers to cause a denial of service (device relo…

Fix: after 7.0
Fix from $1,950 2013-07-18
Intrusion Prevention System HIGH 7.8
CVE-2013-3411

The IDSM-2 drivers in Cisco Intrusion Prevention System (IPS) Software on Cisco Catalyst 6500 devices with an IDSM-2 module allow remote attackers to…

Mitigation only
Fix from $1,950 2013-07-18
Unified Communications Manager HIGH 7.5
CVE-2013-3404

SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows remote attackers to execute arbitrary SQL co…

Mitigation only
Fix from $1,950 2013-07-18
Unified Communications Manager MEDIUM 6.8
CVE-2013-3403

Multiple untrusted search path vulnerabilities in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allow local users to gain privil…

Mitigation only
Fix from $1,600 2013-07-18
Unified Communications Manager MEDIUM 6.8
CVE-2013-3433

Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows local users to gain privileges by le…

Mitigation only
Fix from $1,600 2013-07-18
Unified Communications Manager MEDIUM 6.8
CVE-2013-3434

Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows local users to gain privileges by le…

Mitigation only
Fix from $1,600 2013-07-18
Unified Communications Manager MEDIUM 6.5
CVE-2013-3402

An unspecified function in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to execute arbitrary c…

Mitigation only
Fix from $1,600 2013-07-18
Unified Communications Manager MEDIUM 6.5
CVE-2013-3412

SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to execute arbitra…

Mitigation only
Fix from $1,600 2013-07-18
Secure Access Control System MEDIUM 6.8
CVE-2013-3424

Cross-site request forgery (CSRF) vulnerability in Administration and View pages in Cisco Secure Access Control System (ACS) allows remote attackers …

Mitigation only
Fix from $1,600 2013-07-12
Unified Communications Domain Manager MEDIUM 6.8
CVE-2013-3418

Cisco Unified Communications Domain Manager does not properly allocate memory for GET and POST requests, which allows remote authenticated users to c…

Mitigation only
Fix from $1,600 2013-07-11
Virtualization Experience Client 6000 Series Firmware MEDIUM 6.8
CVE-2013-3408

The firmware on Cisco Virtualization Experience Client 6000 devices sets incorrect operating-system permissions, which allows local users to gain pri…

Mitigation only
Fix from $1,600 2013-07-10
Nx Os MEDIUM 6.8
CVE-2013-3400

The license-installation module in Cisco NX-OS on Nexus 1000V devices allows local users to execute arbitrary commands via crafted "install license" …

Mitigation only
Fix from $1,600 2013-07-10
Content Security Management Appliance MEDIUM 6.8
CVE-2013-3395

Cross-site request forgery (CSRF) vulnerability in the web framework on Cisco IronPort Web Security Appliance (WSA) devices, Email Security Appliance…

Mitigation only
Fix from $1,600 2013-07-02