Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2002-2315EPSS 10%
Cisco IOS 11.2.x and 12.0.x does not limit the size of its redirect table, which allows remote attackers to cause a denial of service (memory consump…
iOS
No fix yet
HIGH 7.8
CVE-2002-2379EPSS 6%
Cisco AS5350 IOS 12.2(11)T with access control lists (ACLs) applied and possibly with ssh running allows remote attackers to cause a denial of servic…
As5350
No fix yet
HIGH 7.5
CVE-2002-1706
Cisco IOS software 11.3 through 12.2 running on Cisco uBR7200 and uBR7100 series Universal Broadband Routers allows remote attackers to modify Data O…
iOS
after 12.2
MEDIUM 6.4
CVE-2002-2139
Cisco PIX Firewall 6.0.3 and earlier, and 6.1.x to 6.1.3, do not delete the duplicate ISAKMP SAs for a user's VPN session, which allows local users t…
Pix Firewall Software
Patch available
MEDIUM 5.0
CVE-2002-1768
Cisco IOS 11.1 through 12.2, when HSRP support is not enabled, allows remote attackers to cause a denial of service (CPU consumption) via randomly si…
iOS
Mitigation only
MEDIUM 5.0
CVE-2002-2037
The Cisco Media Gateway Controller (MGC) in (1) SC2200 7.4 and earlier, (2) VSC3000 9.1 and earlier, (3) PGW 2200 9.1 and earlier, (4) Billing and Ma…
Bams
after 9.1
MEDIUM 5.0
CVE-2002-2052
Cisco 2611 router running IOS 12.1(6.5), possibly an interim release, allows remote attackers to cause a denial of service via port scans such as (1)…
iOS
Mitigation only
MEDIUM 5.0
CVE-2002-2053
The design of the Hot Standby Routing Protocol (HSRP), as implemented on Cisco IOS 12.1, when using IRPAS, allows remote attackers to cause a denial …
iOS
Mitigation only
MEDIUM 5.0
CVE-2002-2140
Buffer overflow in Cisco PIX Firewall 5.2.x to 5.2.8, 6.0.x to 6.0.3, 6.1.x to 6.1.3, and 6.2.x to 6.2.1 allows remote attackers to cause a denial of…
Pix Firewall Software
Patch available
MEDIUM 5.0
CVE-2002-2316
Cisco Catalyst 4000 series switches running CatOS 5.5.5, 6.3.5, and 7.1.2 do not always learn MAC addresses from a single initial packet, which cause…
Catos
No fix yet
HIGH 10.0
CVE-2002-1357EPSS 10%
Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers …
iOS
Mitigation only
HIGH 10.0
CVE-2002-1358EPSS 6%
Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of …
iOS
Mitigation only
HIGH 10.0
CVE-2002-1359EPSS 80%
Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service…
iOS
Mitigation only
HIGH 10.0
CVE-2002-1360EPSS 6%
Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, …
iOS
Mitigation only
HIGH 7.5
CVE-2002-1190
Cisco Unity 2.x and 3.x uses well-known default user accounts, which could allow remote attackers to gain access and place arbitrary calls.
Unity Server
Patch available
HIGH 7.1
CVE-2002-1222EPSS 9%
Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a denial of se…
Catos
Patch available
HIGH 7.5
CVE-2002-0938
Cross-site scripting vulnerability in CiscoSecure ACS 3.0 allows remote attackers to execute arbitrary script or HTML as other web users via the acti…
Secure Access Control Server
No fix yet
HIGH 7.5
CVE-2002-0954
The encryption algorithms for enable and passwd commands on Cisco PIX Firewall can be executed quickly due to a limited number of rounds, which make …
Pix Firewall
Mitigation only
HIGH 7.5
CVE-2002-1092
Cisco VPN 3000 Concentrator 3.6(Rel) and earlier, and 2.x.x, when configured to use internal authentication with group accounts and without any user …
Vpn 3000 Concentrator Series Software
after 3.6
HIGH 7.5
CVE-2002-1096
Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.1, allows restricted administrators to obtain user passwords that are stored in plaintext in HT…
Vpn 3000 Concentrator Series Software
Mitigation only
HIGH 7.5
CVE-2002-1097
Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintex…
Vpn 3000 Concentrator Series Software
Mitigation only
HIGH 7.5
CVE-2002-1098
Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, adds an "HTTPS on Public Inbound (XML-Auto)(forward/in)" rule but sets the protocol to "ANY"…
Vpn 3000 Concentrator Series Software
Mitigation only
HIGH 7.5
CVE-2002-1106
Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.1C, does not properly verify that certificate DN fields match those of …
Vpn Client
Mitigation only
HIGH 7.5
CVE-2002-1107
Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.2B, does not generate sufficiently random numbers, which may make it vu…
Vpn Client
Mitigation only
HIGH 7.1
CVE-2002-1024
Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was …
iOS
Patch available
MEDIUM 6.4
CVE-2002-0882
The web server for Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allows remote attackers to cause a denial of service (reset) and possibly read s…
Voip Phone Cp 7940
Mitigation only
MEDIUM 5.0
CVE-2002-0880
Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allow remote attackers to cause a denial of service (crash) via malformed packets as demonstrated b…
Voip Phone Cp 7940
Mitigation only
MEDIUM 5.0
CVE-2002-0886EPSS 5%
Cisco DSL CPE devices running CBOS 2.4.4 and earlier allows remote attackers to cause a denial of service (hang or memory consumption) via (1) a larg…
Cbos
Patch available
MEDIUM 5.0
CVE-2002-0908
Directory traversal vulnerability in the web server for Cisco IDS Device Manager before 3.1.2 allows remote attackers to read arbitrary files via a .…
Ids Device Manager
Patch available
MEDIUM 5.0
CVE-2002-0952
Cisco ONS15454 optical transport platform running ONS 3.1.0 to 3.2.0 allows remote attackers to cause a denial of service (reset) by sending IP packe…
Optical Networking Systems Software
Patch available