Vulnerability index

Browse CVEs

5,759 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Network Admission Control MEDIUM 5.0
CVE-2006-4430

The Cisco Network Admission Control (NAC) 3.6.4.1 and earlier allows remote attackers to prevent installation of the Cisco Clean Access (CCA) Agent a…

Fix: after 3.6.4.1
Fix from $1,600 2006-08-29
Content Services Switch 11000 MEDIUM 5.0
CVE-2006-4352

The ArrowPoint cookie functionality for Cisco 11000 series Content Service Switches specifies an internal IP address if the administrator does not sp…

No fix yet
Fix from $1,600 2006-08-25
Pix Firewall 501 MEDIUM 6.8
CVE-2006-4312

Cisco PIX 500 Series Security Appliances and ASA 5500 Series Adaptive Security Appliances, when running 7.0(x) up to 7.0(5) and 7.1(x) up to 7.1(2.4)…

Mitigation only
Fix from $1,600 2006-08-23
Vpn 3000 Concentrator Series Software MEDIUM 5.0
CVE-2006-4313EPSS 12%

Multiple unspecified vulnerabilities in Cisco VPN 3000 series concentrators before 4.1, 4.1.x up to 4.1(7)L, and 4.7.x up to 4.7(2)F allow attackers …

Patch available
Fix from $1,600 2006-08-23
Pix Firewall 501 MEDIUM 5.0
CVE-2006-4194

Unspecified vulnerability in Cisco PIX 500 Series Security Appliances allows remote attackers to send arbitrary UDP packets to intranet devices via u…

Mitigation only
Fix from $1,600 2006-08-17
Callmanager Express MEDIUM 5.0
CVE-2006-4032

Unspecified vulnerability in Cisco IOS CallManager Express (CME) allows remote attackers to gain sensitive information (user names) from the Session …

Mitigation only
Fix from $1,600 2006-08-09
iOS MEDIUM 5.0
CVE-2006-3906EPSS 7%

Internet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators, and PIX firewalls, allows remote attackers to ca…

Mitigation only
Fix from $1,600 2006-07-27
Security Monitoring Analysis And Response System HIGH 7.5
CVE-2006-3733EPSS 12%

jmx-console/HtmlAdaptor in the jmx-console in the JBoss web application server, as shipped with Cisco Security Monitoring, Analysis and Response Syst…

Patch available
Fix from $1,950 2006-07-21
Cs Mars HIGH 7.2
CVE-2006-3734

Multiple unspecified vulnerabilities in the Command Line Interface (CLI) for Cisco Security Monitoring, Analysis and Response System (CS-MARS) before…

Patch available
Fix from $1,950 2006-07-21
Cs Mars MEDIUM 5.0
CVE-2006-3732

Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1 ships with an Oracle database that contains several default accounts a…

Patch available
Fix from $1,600 2006-07-21
Unified Callmanager HIGH 7.5
CVE-2006-3594

Buffer overflow in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows remote attackers to execute arbitrary code via a long hostname in a…

Patch available
Fix from $1,950 2006-07-18
Router Web Setup HIGH 7.5
CVE-2006-3595

The default configuration of IOS HTTP server in Cisco Router Web Setup (CRWS) before 3.3.0 build 31 does not require credentials, which allows remote…

Patch available
Fix from $1,950 2006-07-18
Ips Sensor Software MEDIUM 5.0
CVE-2006-3596

The device driver for Intel-based gigabit network adapters in Cisco Intrusion Prevention System (IPS) 5.1(1) through 5.1(p1), as installed on various…

Patch available
Fix from $1,600 2006-07-18
iOS HIGH 9.3
CVE-2006-3291

The web interface on Cisco IOS 12.3(8)JA and 12.3(8)JA1, as used on the Cisco Wireless Access Point and Wireless Bridge, reconfigures itself when it …

Patch available
Fix from $1,950 2006-06-28
Wireless Control System HIGH 7.5
CVE-2006-3286

The internal database in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(63) stores a hard-coded username and password in plaint…

Fix: after 3.2
Fix from $1,950 2006-06-28
Wireless Control System HIGH 7.5
CVE-2006-3287

Cisco Wireless Control System (WCS) for Linux and Windows 4.0(1) and earlier uses a default administrator username "root" and password "public," whic…

Fix: after 4.0
Fix from $1,950 2006-06-28
Wireless Control System MEDIUM 5.0
CVE-2006-3288

Unspecified vulnerability in the TFTP server in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51), when configured to use a di…

Fix: after 3.2
Fix from $1,600 2006-06-28
Wireless Control System MEDIUM 5.0
CVE-2006-3290

HTTP server in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51) stores sensitive information under the web root with insuffic…

Fix: after 3.2
Fix from $1,600 2006-06-28
Wireless Control System HIGH 7.5
CVE-2006-3285

The internal database in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51) uses an undocumented, hard-coded username and passw…

Fix: after 3.2
Fix from $1,950 2006-06-28
Secure Access Control Server HIGH 7.5
CVE-2006-3226

Cisco Secure Access Control Server (ACS) 4.x for Windows uses the client's IP address and the server's port number to grant access to an HTTP server …

Mitigation only
Fix from $1,950 2006-06-26
Vpn Client HIGH 7.2
CVE-2006-2679

Unspecified vulnerability in the VPN Client for Windows Graphical User Interface (GUI) (aka the VPN client dialer) in Cisco VPN Client for Windows 4.…

Patch available
Fix from $1,950 2006-05-31
Application Velocity System 3110 MEDIUM 6.4
CVE-2006-2322

The transparent proxy feature of the Cisco Application Velocity System (AVS) 3110 5.0 and 4.0 and earlier, and 3120 5.0.0 and earlier, has a default …

Patch available
Fix from $1,600 2006-05-12
Secure Access Control Server HIGH 7.2
CVE-2006-0561

Cisco Secure Access Control Server (ACS) 3.x for Windows stores ACS administrator passwords and the master key in the registry with insecure permissi…

Patch available
Fix from $1,950 2006-05-10
Adaptive Security Appliance Software HIGH 7.5
CVE-2006-0515EPSS 10%

Cisco PIX/ASA 7.1.x before 7.1(2) and 7.0.x before 7.0(5), PIX 6.3.x before 6.3.5(112), and FWSM 2.3.x before 2.3(4) and 3.x before 3.1(7), when used…

Patch available
Fix from $1,950 2006-05-09
User Registration Tool HIGH 7.5
CVE-2006-1961

Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13, Hosting Solution Engine (HSE) and User Registration Tool (URT) bef…

Patch available
Fix from $1,950 2006-04-21
Wireless Lan Solution Engine MEDIUM 5.8
CVE-2006-1960EPSS 5%

Cross-site scripting (XSS) vulnerability in the appliance web user interface in Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express…

Patch available
Fix from $1,600 2006-04-21
Ios Xr MEDIUM 5.0
CVE-2006-1927

Cisco IOS XR, when configured for Multi Protocol Label Switching (MPLS) and running on Cisco CRS-1 or Cisco 12000 series routers, allows remote attac…

Mitigation only
Fix from $1,600 2006-04-20
Ios Xr MEDIUM 5.0
CVE-2006-1928

Cisco IOS XR, when configured for Multi Protocol Label Switching (MPLS) and running on Cisco CRS-1 routers, allows remote attackers to cause a denial…

Mitigation only
Fix from $1,600 2006-04-20
Optical Networking Systems Software HIGH 7.8
CVE-2006-1670

Control cards for Cisco Optical Networking System (ONS) 15000 series nodes before 20060405 allow remote attackers to cause a denial of service (memor…

Patch available
Fix from $1,950 2006-04-07
Transport Controller HIGH 7.5
CVE-2006-1672

The installation of Cisco Transport Controller (CTC) for Cisco Optical Networking System (ONS) 15000 series nodes adds a Java policy file entry with …

Mitigation only
Fix from $1,950 2006-04-07