Vulnerability index

Browse CVEs

5,759 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Secure Access Control Server HIGH 7.5
CVE-2004-1460

Cisco Secure Access Control Server (ACS) 3.2(3) and earlier, when configured with an anonymous bind in Novell Directory Services (NDS) and authentica…

Patch available
Fix from $1,950 2004-12-31
Secure Access Control Server HIGH 7.5
CVE-2004-1461

Cisco Secure Access Control Server (ACS) 3.2(3) and earlier spawns a separate unauthenticated TCP connection on a random port when a user authenticat…

Patch available
Fix from $1,950 2004-12-31
iOS MEDIUM 5.9
CVE-2004-1464 KEV

Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP c…

Fix: after 12.2
Fix from $1,600 2004-12-31
Optical Networking Systems Software MEDIUM 5.0
CVE-2004-1432

Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.6(0) and 4.6(1), 4.5(x), 4.1(0) to 4.1(3), 4.0(0) to 4.0(2), and earl…

Mitigation only
Fix from $1,600 2004-12-31
Optical Networking Systems Software MEDIUM 5.0
CVE-2004-1433

Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.6(0) and 4.6(1), 4.5(x), 4.1(0) to 4.1(3), 4.0(0) to 4.0(2), and earl…

Mitigation only
Fix from $1,600 2004-12-31
Optical Networking Systems Software MEDIUM 5.0
CVE-2004-1434

Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.1(0) to 4.1(2), 4.5(x), 4.0(0) to 4.0(2), and earlier versions, allow…

No fix yet
Fix from $1,600 2004-12-31
Optical Networking Systems Software MEDIUM 5.0
CVE-2004-1435

Multiple versions of Cisco ONS 15327, ONS 15454, and ONS 15454 SDH, including 4.6(0) and 4.6(1), 4.5(x), 4.1(0) to 4.1(3), 4.0(0) to 4.0(2), and earl…

Mitigation only
Fix from $1,600 2004-12-31
iOS MEDIUM 5.0
CVE-2004-1454

Cisco IOS 12.0S, 12.2, and 12.3, with Open Shortest Path First (OSPF) enabled, allows remote attackers to cause a denial of service (device reload) v…

Patch available
Fix from $1,600 2004-12-31
Secure Access Control Server MEDIUM 5.0
CVE-2004-1458

The CSAdmin web administration interface for Cisco Secure Access Control Server (ACS) 3.2(2) build 15 allows remote attackers to cause a denial of se…

Patch available
Fix from $1,600 2004-12-31
iOS MEDIUM 5.0
CVE-2004-1775

Cisco VACM (View-based Access Control MIB) for Catalyst Operating Software (CatOS) 5.5 and 6.1 and IOS 12.0 and 12.1 allows remote attackers to read …

Patch available
Fix from $1,600 2004-12-31
Unity Server HIGH 7.5
CVE-2004-1322

Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers…

Patch available
Fix from $1,950 2004-12-15
Optical Networking Systems Software HIGH 10.0
CVE-2004-0308

Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS15600 before 1.3(0) allows …

Patch available
Fix from $1,950 2004-11-24
Firewall Services Module HIGH 7.5
CVE-2004-0079EPSS 10%

The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) vi…

Mitigation only
Fix from $1,950 2004-11-23
Firewall Services Module MEDIUM 5.0
CVE-2004-0081EPSS 7%

OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop…

Mitigation only
Fix from $1,600 2004-11-23
Firewall Services Module MEDIUM 5.0
CVE-2004-0112EPSS 10%

The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos …

Mitigation only
Fix from $1,600 2004-11-23
Optical Networking Systems Software MEDIUM 5.0
CVE-2004-0306

Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), ONS 15454 SD before 4.1(3), and Cisco ONS 15600 before 1.3(0) enable TFTP service on UDP port…

Patch available
Fix from $1,600 2004-11-23
Optical Networking Systems Software MEDIUM 5.0
CVE-2004-0307

Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(1), and ONS 15454 SD before 4.1(3) allows remote attackers to cause a denial of service (reset) b…

Patch available
Fix from $1,600 2004-11-23
Content Services Switch 11000 MEDIUM 5.0
CVE-2004-0352

Cisco 11000 Series Content Services Switches (CSS) running WebNS 5.0(x) before 05.0(04.07)S, and 6.10(x) before 06.10(02.05)S allow remote attackers …

Patch available
Fix from $1,600 2004-11-23
Catos MEDIUM 5.0
CVE-2004-0551

Cisco CatOS 5.x before 5.5(20) through 8.x before 8.2(2) and 8.3(2)GLX, as used in Catalyst switches, allows remote attackers to cause a denial of se…

Mitigation only
Fix from $1,600 2004-08-06
iOS MEDIUM 5.0
CVE-2004-0710

IP Security VPN Services Module (VPNSM) in Cisco Catalyst 6500 Series Switch and the Cisco 7600 Series Internet Routers running IOS before 12.2(17b)S…

Patch available
Fix from $1,600 2004-07-27
iOS MEDIUM 5.0
CVE-2004-0714

Cisco Internetwork Operating System (IOS) 12.0S through 12.3T attempts to process SNMP solicited operations on improper ports (UDP 162 and a randomly…

Patch available
Fix from $1,600 2004-07-27
Wireless Lan Solution Engine HIGH 10.0
CVE-2004-0391

Cisco Wireless LAN Solution Engine (WLSE) 2.0 through 2.5 and Hosting Solution Engine (HSE) 1.7 through 1.7.3 have a hardcoded username and password,…

Patch available
Fix from $1,950 2004-06-01
iOS HIGH 7.5
CVE-2004-0054

Multiple vulnerabilities in the H.323 protocol implementation for Cisco IOS 11.3T through 12.2T allow remote attackers to cause a denial of service a…

Patch available
Fix from $1,950 2004-02-17
Personal Assistant HIGH 7.5
CVE-2004-0044

Cisco Personal Assistant 1.4(1) and 1.4(2) disables password authentication when "Allow Only Cisco CallManager Users" is enabled and the Corporate Di…

Patch available
Fix from $1,950 2004-02-03
Emergency Responder HIGH 10.0
CVE-2004-1760

The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authenticat…

Patch available
Fix from $1,950 2004-01-21
Emergency Responder MEDIUM 5.0
CVE-2004-1759

Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CP…

Patch available
Fix from $1,600 2004-01-21
Pix Firewall HIGH 7.8
CVE-2003-1003

Cisco PIX firewall 5.x.x, and 6.3.1 and earlier, allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when s…

Patch available
Fix from $1,950 2004-01-05
Application And Content Networking Software HIGH 7.5
CVE-2003-0982

Buffer overflow in the authentication module for Cisco ACNS 4.x before 4.2.11, and 5.x before 5.0.5, allows remote attackers to execute arbitrary cod…

Patch available
Fix from $1,950 2004-01-05
80 7111 01 For The Unity Svrx255 1a HIGH 7.5
CVE-2003-0983

Cisco Unity on IBM servers is shipped with default settings that should have been disabled by the manufacturer, which allows local or remote attacker…

Patch available
Fix from $1,950 2004-01-05
Catalyst 6500 MEDIUM 5.0
CVE-2003-1001

Buffer overflow in the Cisco Firewall Services Module (FWSM) in Cisco Catalyst 6500 and 7600 series devices allows remote attackers to cause a denial…

Patch available
Fix from $1,600 2004-01-05