Vulnerability index

Browse CVEs

5,759 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Anyconnect Secure Mobility Client HIGH 9.3
CVE-2012-3088

Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495, and 3.2.x, does not check whether an HTTP request originally contains ScanSafe header…

Mitigation only
Fix from $1,950 2012-09-16
Unity Connection HIGH 7.8
CVE-2012-3060

Cisco Unity Connection (UC) 8.6, 9.0, and 9.5 allows remote attackers to cause a denial of service (CPU consumption) via malformed UDP packets, aka B…

Mitigation only
Fix from $1,950 2012-09-16
iOS HIGH 7.8
CVE-2012-3079

Cisco IOS 12.2 allows remote attackers to cause a denial of service (CPU consumption) by establishing many IPv6 neighbors, aka Bug ID CSCtn78957.

Mitigation only
Fix from $1,950 2012-09-16
Vpn Client MEDIUM 6.9
CVE-2012-3052

Untrusted search path vulnerability in Cisco VPN Client 5.0 allows local users to gain privileges via a Trojan horse DLL in the current working direc…

Mitigation only
Fix from $1,600 2012-09-16
iOS MEDIUM 6.3
CVE-2012-3893

The FlexVPN implementation in Cisco IOS 15.2 and 15.3 allows remote authenticated users to cause a denial of service (spoke crash) via spoke-to-spoke…

Mitigation only
Fix from $1,600 2012-09-16
iOS MEDIUM 6.3
CVE-2012-3895

Cisco IOS 15.0 through 15.3 allows remote authenticated users to cause a denial of service (device crash) via an MVPNv6 update, aka Bug ID CSCty89224.

Mitigation only
Fix from $1,600 2012-09-16
Nx Os MEDIUM 6.1
CVE-2012-3051

Cisco NX-OS 5.2 and 6.1 on Nexus 7000 series switches allows remote attackers to cause a denial of service (process crash or packet loss) via a large…

Mitigation only
Fix from $1,600 2012-09-16
Anyconnect Secure Mobility Client MEDIUM 5.0
CVE-2012-3094

The VPN downloader in the download_install component in Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495 on Linux accepts arbitrary X.5…

Mitigation only
Fix from $1,600 2012-09-16
Intrusion Prevention System MEDIUM 5.0
CVE-2012-3899

sensorApp on Cisco IPS 4200 series sensors 6.0, 6.2, and 7.0 does not properly allocate memory, which allows remote attackers to cause a denial of se…

Mitigation only
Fix from $1,600 2012-09-16
Intrusion Prevention System MEDIUM 5.0
CVE-2012-3901

The updateTime function in sensorApp on Cisco IPS 4200 series sensors 7.0 and 7.1 allows remote attackers to cause a denial of service (process crash…

Mitigation only
Fix from $1,600 2012-09-16
Unified Presence HIGH 7.8
CVE-2012-3935

Cisco Unified Presence (CUP) before 8.6(3) and Jabber Extensible Communications Platform (aka Jabber XCP) before 5.3 allow remote attackers to cause …

Fix: after 8.6
Fix from $1,950 2012-09-12
Asa Cx Context Aware Security HIGH 7.8
CVE-2012-4629

The Cisco ASA-CX Context-Aware Security module before 9.0.2-103 for Adaptive Security Appliances (ASA) devices, and Prime Security Manager (aka PRSM)…

Fix: after 9.0
Fix from $1,950 2012-09-12
Nx Os MEDIUM 5.0
CVE-2012-1357

The igmp_snoop_orib_fill_source_update function in the IGMP process in NX-OS 5.0 and 5.1 on Cisco Nexus 5000 series switches allows remote attackers …

Mitigation only
Fix from $1,600 2012-08-06
iOS HIGH 7.8
CVE-2012-1350

Cisco IOS 12.3 and 12.4 on Aironet access points allows remote attackers to cause a denial of service (radio-interface input-queue hang) via IAPP 0x3…

Mitigation only
Fix from $1,950 2012-08-06
Emergency Responder MEDIUM 5.0
CVE-2012-1346

Cisco Emergency Responder 8.6 and 9.2 allows remote attackers to cause a denial of service (CPU consumption) by sending malformed UDP packets to the …

Mitigation only
Fix from $1,600 2012-08-06
Wide Area Application Services MEDIUM 5.0
CVE-2012-1348

Cisco Wide Area Application Services (WAAS) appliances with software 4.4, 5.0, and 5.1 include a one-way hash of a password within output text, which…

Mitigation only
Fix from $1,600 2012-08-06
Anyconnect Secure Mobility Client MEDIUM 5.8
CVE-2012-2499

The IPsec implementation in Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 does not verify the certificate name in an X.509 certificate…

Mitigation only
Fix from $1,600 2012-08-06
Ip Communicator MEDIUM 5.0
CVE-2012-2490

Cisco IP Communicator 8.6 allows man-in-the-middle attackers to modify the Certificate Trust List via unspecified vectors, aka Bug ID CSCtz01471.

No fix yet
Fix from $1,600 2012-08-06
Nx Os HIGH 7.8
CVE-2012-2469

Cisco NX-OS 4.2, 5.0, 5.1, and 5.2 on Nexus 7000 series switches, when the High Availability (HA) policy is configured for Reset, allows remote attac…

Mitigation only
Fix from $1,950 2012-08-06
Adaptive Security Appliance Software HIGH 7.8
CVE-2012-2472

Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 and 8.4, when SIP inspection is enabled, create many identical pre-all…

Mitigation only
Fix from $1,950 2012-08-06
iOS MEDIUM 6.3
CVE-2012-1338

Cisco IOS 15.0 and 15.1 on Catalyst 3560 and 3750 series switches allows remote authenticated users to cause a denial of service (device reload) by c…

Mitigation only
Fix from $1,600 2012-08-06
Carrier Routing System MEDIUM 5.8
CVE-2012-1342

Cisco Carrier Routing System (CRS) 3.9, 4.0, and 4.1 allows remote attackers to bypass ACL entries via fragmented packets, aka Bug ID CSCtj10975.

Mitigation only
Fix from $1,600 2012-08-06
Unified Computing System Infrastructure And Unified Computing System Software MEDIUM 5.0
CVE-2012-1339

The Fabric Interconnect component in Cisco Unified Computing System (UCS) 2.0 allows remote attackers to cause a denial of service (process crash) vi…

Mitigation only
Fix from $1,600 2012-08-06
Mds 9000 Nx Os MEDIUM 5.0
CVE-2012-1340

The Fibre Channel over IP (FCIP) implementation in Cisco MDS NX-OS 4.2 and 5.2 on MDS 9000 series switches allows remote attackers to cause a denial …

Mitigation only
Fix from $1,600 2012-08-06
iOS MEDIUM 5.0
CVE-2012-1367

The MallocLite implementation in Cisco IOS 12.0, 12.2, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (Route Processor cra…

No fix yet
Fix from $1,600 2012-08-06
Linksys Playerpt Activex Control HIGH 9.3
CVE-2012-0284EPSS 36%

Stack-based buffer overflow in the SetSource method in the Cisco Linksys PlayerPT ActiveX control 1.0.0.15 in PlayerPT.ocx on the Cisco WVC200 Wirele…

Mitigation only
Fix from $1,950 2012-07-19
Telepresence System Software HIGH 9.0
CVE-2012-3075

The administrative web interface on Cisco TelePresence Immersive Endpoint Devices before 1.7.4 allows remote authenticated users to execute arbitrary…

Fix: after 1.7.2
Fix from $1,950 2012-07-12
Telepresence Recording Server HIGH 9.0
CVE-2012-3076

The administrative web interface on Cisco TelePresence Recording Server before 1.8.0 allows remote authenticated users to execute arbitrary commands …

Fix: after 1.7.3
Fix from $1,950 2012-07-12
Telepresence Multipoint Switch Software HIGH 8.3
CVE-2012-2486

The Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1.9.0, Cisco TelePresence Immersive Endpoint Devices…

Fix: after 1.9.0.1
Fix from $1,950 2012-07-12
Telepresence System Software HIGH 8.3
CVE-2012-3074

An unspecified API on Cisco TelePresence Immersive Endpoint Devices before 1.9.1 allows remote attackers to execute arbitrary commands by leveraging …

Fix: after 1.9.0.1
Fix from $1,950 2012-07-12