Lucene search

K

Cisco Security Vulnerabilities

cve
cve

CVE-2013-3399

Buffer overflow in an unspecified Android API on the Cisco Desktop Collaboration Experience DX650 allows attackers to execute arbitrary code via vectors that leverage incorrect memory allocation, aka Bug IDs CSCuf93957, CSCug22352, and CSCug22462.

7.9AI Score

0.0004EPSS

2022-10-03 04:14 PM
19
cve
cve

CVE-2013-3400

The license-installation module in Cisco NX-OS on Nexus 1000V devices allows local users to execute arbitrary commands via crafted "install license" arguments, aka Bug ID CSCuh30824.

7.5AI Score

0.0004EPSS

2013-07-10 08:55 PM
18
cve
cve

CVE-2013-3401

The SIP implementation in Cisco TelePresence TC Software allows remote attackers to trigger unintended use of NOTIFY messages via unspecified vectors, aka Bug ID CSCud96080.

6.9AI Score

0.001EPSS

2022-10-03 04:14 PM
20
cve
cve

CVE-2013-3402

An unspecified function in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to execute arbitrary commands via unknown vectors, aka Bug ID CSCuh73440.

7.4AI Score

0.001EPSS

2013-07-18 12:48 PM
25
cve
cve

CVE-2013-3403

Multiple untrusted search path vulnerabilities in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allow local users to gain privileges by leveraging unspecified file-permission and environment-variable issues for privileged programs, aka Bug ID CSCuh73454.

6.9AI Score

0.001EPSS

2013-07-18 12:48 PM
20
cve
cve

CVE-2013-3404

SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, leading to discovery of encrypted credentials by leveraging metadata, aka Bug ID CSCuh01051.

8.6AI Score

0.001EPSS

2013-07-18 12:48 PM
23
cve
cve

CVE-2013-3405

The web portal in TC software on Cisco TelePresence endpoints does not require an exact password match during a login attempt by a user who has not configured a password, which allows remote attackers to bypass authentication by sending an arbitrary password, aka Bug ID CSCud96071.

7.4AI Score

0.001EPSS

2022-10-03 04:14 PM
17
cve
cve

CVE-2013-3406

The "Files Available for Download" implementation in the Cisco Intelligent Automation for Cloud component in Cisco Services Portal 9.4(1) allows remote authenticated users to read arbitrary files via a crafted request, aka Bug ID CSCug65687.

6.4AI Score

0.001EPSS

2022-10-03 04:14 PM
18
cve
cve

CVE-2013-3407

The web interface in Cisco Server Provisioner 6.4.0 Patch 5-1301292331 and earlier does not require authentication for unspecified pages, which allows remote attackers to obtain sensitive information via a direct request, aka Bug ID CSCug65664.

6.6AI Score

0.002EPSS

2022-10-03 04:14 PM
18
cve
cve

CVE-2013-3408

The firmware on Cisco Virtualization Experience Client 6000 devices sets incorrect operating-system permissions, which allows local users to gain privileges via an unspecified sequence of commands, aka Bug ID CSCuc31764.

7AI Score

0.001EPSS

2013-07-10 09:55 PM
24
cve
cve

CVE-2013-3409

The portal in Cisco Prime Central for Hosted Collaboration Solution (HCS) places cleartext credentials in temporary files, which allows local users to obtain sensitive information by leveraging weak file permissions to read these files, aka Bug IDs CSCuh33735 and CSCuh34230.

5.9AI Score

0.0004EPSS

2022-10-03 04:14 PM
21
cve
cve

CVE-2013-3410

Cisco Intrusion Prevention System (IPS) Software on IPS NME devices before 7.0(9)E4 allows remote attackers to cause a denial of service (device reload) via malformed IPv4 packets that trigger incorrect memory allocation, aka Bug ID CSCua61977.

6.9AI Score

0.002EPSS

2013-07-18 12:48 PM
20
cve
cve

CVE-2013-3411

The IDSM-2 drivers in Cisco Intrusion Prevention System (IPS) Software on Cisco Catalyst 6500 devices with an IDSM-2 module allow remote attackers to cause a denial of service (device hang) via malformed IPv4 TCP packets, aka Bug ID CSCuh27460.

6.9AI Score

0.002EPSS

2013-07-18 12:48 PM
21
cve
cve

CVE-2013-3412

SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuh81766.

8.1AI Score

0.001EPSS

2013-07-18 12:48 PM
16
cve
cve

CVE-2013-3413

Cross-site scripting (XSS) vulnerability in the search form in the administration/monitoring panel on the Cisco Identity Services Engine (ISE) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuh87036.

5.9AI Score

0.001EPSS

2022-10-03 04:14 PM
20
cve
cve

CVE-2013-3414

Cross-site scripting (XSS) vulnerability in the WebVPN portal login page on Cisco Adaptive Security Appliances (ASA) devices allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCug83080.

5.8AI Score

0.002EPSS

2013-07-25 03:53 PM
19
2
cve
cve

CVE-2013-3415

Cisco Adaptive Security Appliance (ASA) Software 8.4.x before 8.4(3) and 8.6.x before 8.6(1.3) does not properly manage memory upon an AnyConnect SSL VPN client disconnection, which allows remote attackers to cause a denial of service (memory consumption, and forwarding outage or system hang) via p...

6.9AI Score

0.002EPSS

2013-10-13 10:20 AM
19
cve
cve

CVE-2013-3416

Cross-site scripting (XSS) vulnerability in the web framework in the unified-communications management implementation in Cisco Unified Operations Manager and Unified Service Monitor allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug IDs CSCuh47574 a...

5.9AI Score

0.002EPSS

2013-07-10 09:55 PM
17
cve
cve

CVE-2013-3417

The administrative web interface in Cisco Video Surveillance Operations Manager does not properly perform authentication, which allows remote attackers to watch video feeds via a crafted URL, aka Bug ID CSCtg72262.

6.8AI Score

0.002EPSS

2022-10-03 04:14 PM
18
cve
cve

CVE-2013-3418

Cisco Unified Communications Domain Manager does not properly allocate memory for GET and POST requests, which allows remote authenticated users to cause a denial of service (memory consumption and process crash) via crafted requests to the management interface, aka Bug ID CSCud22922.

6.5AI Score

0.001EPSS

2022-10-03 04:14 PM
21
cve
cve

CVE-2013-3419

Cross-site scripting (XSS) vulnerability in Cisco Unified MeetingPlace Web Conferencing allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuh74981.

5.9AI Score

0.001EPSS

2022-10-03 04:14 PM
18
cve
cve

CVE-2013-3420

Cross-site request forgery (CSRF) vulnerability in the web framework on the Cisco Identity Services Engine (ISE) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuh25506.

7.4AI Score

0.001EPSS

2022-10-03 04:14 PM
17
cve
cve

CVE-2013-3421

Cross-site scripting (XSS) vulnerability in the Help index page in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCud75170.

5.8AI Score

0.001EPSS

2013-07-12 09:55 PM
17
cve
cve

CVE-2013-3422

Cross-site scripting (XSS) vulnerability in Administration pages in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCud75165.

5.8AI Score

0.001EPSS

2013-07-12 09:55 PM
22
cve
cve

CVE-2013-3423

Cross-site scripting (XSS) vulnerability in the web interface in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified field, aka Bug ID CSCud75174.

5.8AI Score

0.001EPSS

2013-07-12 09:55 PM
22
cve
cve

CVE-2013-3424

Cross-site request forgery (CSRF) vulnerability in Administration and View pages in Cisco Secure Access Control System (ACS) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCud75177.

7.3AI Score

0.001EPSS

2013-07-12 09:55 PM
20
cve
cve

CVE-2013-3425

The Meeting Center component in Cisco WebEx 11 generates different error messages for invalid file-access attempts depending on whether a file exists, which allows remote authenticated users to enumerate files via a series of SPI calls, aka Bug ID CSCuc35965.

6.4AI Score

0.001EPSS

2013-07-31 01:20 PM
21
cve
cve

CVE-2013-3426

The Serviceability servlet on Cisco 9900 IP phones does not properly restrict paths, which allows remote attackers to read arbitrary files by specifying a pathname in a file request, aka Bug ID CSCuh52810.

6.8AI Score

0.002EPSS

2022-10-03 04:14 PM
27
cve
cve

CVE-2013-3428

The web interface in Cisco Secure Access Control System (ACS) does not properly suppress error-condition details, which allows remote authenticated users to obtain sensitive information via an unspecified request that triggers an error, aka Bug ID CSCue65957.

5.9AI Score

0.001EPSS

2022-10-03 04:14 PM
19
cve
cve

CVE-2013-3429

Multiple directory traversal vulnerabilities in Cisco Video Surveillance Manager (VSM) before 7.0.0 allow remote attackers to read system files via a crafted URL, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv37163.

6.8AI Score

0.003EPSS

2013-07-25 03:53 PM
28
cve
cve

CVE-2013-3430

Cisco Video Surveillance Manager (VSM) before 7.0.0 allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv37288.

6.4AI Score

0.006EPSS

2013-07-25 03:53 PM
22
cve
cve

CVE-2013-3431

Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages, which allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) pack...

6.7AI Score

0.003EPSS

2013-07-25 03:53 PM
29
cve
cve

CVE-2013-3433

Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows local users to gain privileges by leveraging unspecified file-permission and environment-variable issues for privileged programs, aka Bug ID CSCui02276.

6.7AI Score

0.0004EPSS

2013-07-18 12:48 PM
17
cve
cve

CVE-2013-3434

Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows local users to gain privileges by leveraging unspecified file-permission and environment-variable issues for privileged programs, aka Bug ID CSCui02242.

6.7AI Score

0.0004EPSS

2013-07-18 12:48 PM
18
cve
cve

CVE-2013-3435

The Cisco Unified IP Conference Station 7937G allows remote attackers to cause a denial of service (networking outage) via a flood of TCP packets, aka Bug ID CSCuh42052.

6.8AI Score

0.006EPSS

2013-07-23 11:03 AM
24
cve
cve

CVE-2013-3436

The default configuration of the Group Encrypted Transport VPN (GET VPN) feature on Cisco IOS uses an improper mechanism for enabling Group Domain of Interpretation (GDOI) traffic flow, which allows remote attackers to bypass the encryption policy via certain uses of UDP port 848, aka Bug ID CSCui0...

7AI Score

0.005EPSS

2013-07-19 02:36 PM
23
cve
cve

CVE-2013-3437

SQL injection vulnerability in the management application in Cisco Unified Operations Manager allows remote authenticated users to execute arbitrary SQL commands via an entry field, aka Bug ID CSCud80179.

8.2AI Score

0.001EPSS

2013-07-23 11:03 AM
25
cve
cve

CVE-2013-3438

The web framework in the server in Cisco Unified MeetingPlace Web Conferencing allows remote attackers to bypass intended access restrictions and read unspecified web pages via crafted parameters, aka Bug ID CSCuh86385.

6.9AI Score

0.002EPSS

2013-07-24 12:01 PM
20
cve
cve

CVE-2013-3439

Cross-site scripting (XSS) vulnerability in Cisco Unified Operations Manager allows remote attackers to inject arbitrary web script or HTML via a crafted URL in an unspecified HTTP header field, aka Bug ID CSCud80182.

5.8AI Score

0.003EPSS

2013-07-23 05:20 PM
22
cve
cve

CVE-2013-3440

Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface in Cisco Unified Operations Manager allow remote attackers to inject arbitrary web script or HTML, and obtain improperly secured cookies, via unspecified vectors, aka Bug ID CSCud80186.

6AI Score

0.003EPSS

2013-07-23 05:20 PM
22
cve
cve

CVE-2013-3441

Cisco Aironet 3600 access points allow remote attackers to cause a denial of service (memory corruption and device crash) by disrupting Cisco Wireless LAN Controller communication and consequently forcing many transitions from FlexConnect mode to Standalone mode, aka Bug ID CSCuh71210.

7.1AI Score

0.013EPSS

2013-07-23 11:03 AM
24
cve
cve

CVE-2013-3442

The web portal in Cisco Unified Communications Manager (Unified CM) allows remote authenticated users to obtain sensitive stack-trace information via unspecified vectors that trigger a stack exception, aka Bug ID CSCug34854.

5.9AI Score

0.001EPSS

2022-10-03 04:14 PM
17
cve
cve

CVE-2013-3443

The web service framework in Cisco WAAS Software 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1 in a Central Manager (CM) configuration allows remote attackers to execute arbitrary code via a crafted POST request, aka Bug ID CSCuh26626.

7.8AI Score

0.092EPSS

2013-08-01 01:32 PM
21
cve
cve

CVE-2013-3444

The web framework in Cisco WAAS Software before 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1; Cisco ACNS Software 4.x and 5.x before 5.5.29.2; Cisco ECDS Software 2.x before 2.5.6; Cisco CDS-IS Software 2.x before 2.6.3.b50 and 3.1.x before 3.1.2b54; Cisco VDS-IS Software ...

7.4AI Score

0.005EPSS

2013-08-01 01:32 PM
23
cve
cve

CVE-2013-3445

The firewall subsystem in Cisco Identity Services Engine has an incorrect rule for open ports, which allows remote attackers to cause a denial of service (CPU consumption or process crash) via a flood of malformed IP packets, aka Bug ID CSCug94572.

6.9AI Score

0.015EPSS

2013-07-29 01:59 PM
19
cve
cve

CVE-2013-3446

Open redirect vulnerability in the login page in Cisco Digital Media Manager (DMM) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCub23849.

7AI Score

0.001EPSS

2022-10-03 04:14 PM
18
cve
cve

CVE-2013-3448

Cisco WebEx Meetings Server does not check whether a user account is active, which allows remote authenticated users to bypass intended access restrictions by performing meeting operations after account deactivation, aka Bug ID CSCuh33315.

6.4AI Score

0.001EPSS

2013-08-02 12:10 PM
28
cve
cve

CVE-2013-3450

Cross-site request forgery (CSRF) vulnerability in the User WebDialer page in Cisco Unified Communications Manager (Unified CM) allows remote attackers to hijack the authentication of arbitrary users for requests that dial calls, aka Bug ID CSCui13028.

7.4AI Score

0.001EPSS

2022-10-03 04:14 PM
17
cve
cve

CVE-2013-3451

Multiple cross-site request forgery (CSRF) vulnerabilities in Cisco Unified Communications Manager (Unified CM) allow remote attackers to hijack the authentication of arbitrary users for requests that perform arbitrary Unified CM operations, aka Bug ID CSCui13033.

7.5AI Score

0.001EPSS

2022-10-03 04:14 PM
20
cve
cve

CVE-2013-3453

Memory leak in Cisco Unified Communications Manager IM and Presence Service before 8.6(5)SU1 and 9.x before 9.1(2), and Cisco Unified Presence, allows remote attackers to cause a denial of service (memory and CPU consumption) by making many TCP connections to port (1) 5060 or (2) 5061, aka Bug ID C...

6.8AI Score

0.001EPSS

2022-10-03 04:14 PM
27
Total number of security vulnerabilities6090