Filtered by vendor Cisco
Subscribe
Total
6072 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2014-3278 | 1 Cisco | 1 Unified Communications Domain Manager | 2015-12-04 | 5.0 MEDIUM | N/A |
The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) does not properly implement access control, which allows remote attackers to enumerate accounts by visiting an unspecified BVSMWeb web page, aka Bug IDs CSCun39619 and CSCun45572. | |||||
CVE-2014-3323 | 1 Cisco | 1 Unified Contact Center Enterprise | 2015-12-03 | 4.0 MEDIUM | N/A |
Directory traversal vulnerability in Cisco Unified Contact Center Enterprise allows remote authenticated users to read arbitrary web-root files via a crafted URL, aka Bug ID CSCun25262. | |||||
CVE-2014-3307 | 1 Cisco | 1 Universal Small Cell Series Firmware | 2015-12-03 | 6.8 MEDIUM | N/A |
The DHCP client implementation in Universal Small Cell firmware on Cisco Small Cell products allows remote attackers to execute arbitrary commands via crafted DHCP messages, aka Bug ID CSCup47513. | |||||
CVE-2014-3298 | 1 Cisco | 1 Cloud Portal | 2015-12-03 | 4.0 MEDIUM | N/A |
Form Data Viewer in Cisco Intelligent Automation for Cloud in Cisco Cloud Portal places passwords in form data, which allows remote authenticated users to obtain sensitive information by reading HTML source code, aka Bug ID CSCui36976. | |||||
CVE-2014-3297 | 1 Cisco | 1 Cloud Portal | 2015-12-03 | 4.0 MEDIUM | N/A |
Cisco Intelligent Automation for Cloud in Cisco Cloud Portal does not properly restrict the content of MyServices action URLs, which allows remote authenticated users to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, aka Bug IDs CSCui36937, CSCui37004, and CSCui36927. | |||||
CVE-2015-0680 | 1 Cisco | 1 Unified Callmanager | 2015-11-30 | 4.0 MEDIUM | N/A |
Cisco Unified Call Manager (CM) 9.1(2.1000.28) does not properly restrict resource requests, which allows remote authenticated users to read arbitrary files via unspecified vectors, aka Bug ID CSCuq44439. | |||||
CVE-2014-2130 | 1 Cisco | 1 Secure Access Control System | 2015-11-30 | 6.5 MEDIUM | N/A |
Cisco Secure Access Control Server (ACS) provides an unintentional administration web interface based on Apache Tomcat, which allows remote authenticated users to modify application files and configuration files, and consequently execute arbitrary code, by leveraging administrative privileges, aka Bug ID CSCuj83189. | |||||
CVE-2015-0618 | 1 Cisco | 3 Carrier Routing System, Ios Xr, Network Convergence System 6000 | 2015-11-27 | 7.1 HIGH | N/A |
Cisco IOS XR 5.0.1 and 5.2.1 on Network Convergence System (NCS) 6000 devices and 5.1.3 and 5.1.4 on Carrier Routing System X (CRS-X) devices allows remote attackers to cause a denial of service (line-card reload) via malformed IPv6 packets with extension headers, aka Bug ID CSCuq95241. | |||||
CVE-2015-0584 | 1 Cisco | 1 Desktop Collaboration Experience Dx650 | 2015-11-27 | 7.2 HIGH | N/A |
The image-upgrade implementation on Cisco Desktop Collaboration Experience (aka Collaboration Desk Experience or DX) DX650 endpoints allows local users to execute arbitrary OS commands via an unspecified parameter, aka Bug ID CSCus38947. | |||||
CVE-2015-6380 | 1 Cisco | 1 Firepower Extensible Operating System | 2015-11-24 | 6.5 MEDIUM | N/A |
An unspecified script in the web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenticated users to execute arbitrary OS commands via crafted parameters, aka Bug ID CSCux10622. | |||||
CVE-2015-6377 | 1 Cisco | 1 Virtual Topology System | 2015-11-24 | 7.8 HIGH | N/A |
Cisco Virtual Topology System (VTS) 2.0(0) and 2.0(1) allows remote attackers to cause a denial of service (CPU and memory consumption, and TCP port outage) via a flood of crafted TCP packets, aka Bug ID CSCux13379. | |||||
CVE-2015-6376 | 1 Cisco | 1 Telepresence Video Communication Server Software | 2015-11-23 | 6.8 MEDIUM | N/A |
Cross-site request forgery (CSRF) vulnerability in Cisco TelePresence Video Communication Server (VCS) X8.5.1 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuv72412. | |||||
CVE-2015-6374 | 1 Cisco | 1 Firepower Extensible Operating System | 2015-11-19 | 4.3 MEDIUM | N/A |
The web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, aka Bug ID CSCux10604. | |||||
CVE-2015-6373 | 1 Cisco | 1 Firepower Extensible Operating System | 2015-11-19 | 6.8 MEDIUM | N/A |
Cross-site request forgery (CSRF) vulnerability in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCux10611. | |||||
CVE-2015-6372 | 1 Cisco | 1 Firepower Extensible Operating System | 2015-11-19 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCux10614. | |||||
CVE-2015-6371 | 1 Cisco | 1 Firepower Extensible Operating System | 2015-11-19 | 4.0 MEDIUM | N/A |
Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenticated users to read arbitrary files via crafted parameters to unspecified scripts, aka Bug ID CSCux10621. | |||||
CVE-2015-6370 | 1 Cisco | 1 Firepower Extensible Operating System | 2015-11-19 | 7.2 HIGH | N/A |
The Management I/O (MIO) component in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows local users to execute arbitrary OS commands as root via crafted CLI input, aka Bug ID CSCux10578. | |||||
CVE-2015-6369 | 1 Cisco | 1 Firepower Extensible Operating System | 2015-11-19 | 4.9 MEDIUM | N/A |
The USB driver in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows physically proximate attackers to cause a denial of service via a crafted USB device that triggers invalid USB commands, aka Bug ID CSCux10531. | |||||
CVE-2015-6368 | 1 Cisco | 1 Firepower Extensible Operating System | 2015-11-19 | 5.0 MEDIUM | N/A |
Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to read files via a crafted HTTP request, aka Bug ID CSCux10608. | |||||
CVE-2015-6330 | 1 Cisco | 1 Prime Collaboration Assurance | 2015-11-18 | 6.8 MEDIUM | N/A |
Cross-site request forgery (CSRF) vulnerability in Cisco Prime Collaboration Assurance 10.5(1) and 10.6 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCus62712. |