Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2016-07-28 CVE-2016-1467 Resource Management Errors vulnerability in Cisco Videoscape Session Resource Manager
Cisco Videoscape Session Resource Manager (VSRM) allows remote attackers to cause a denial of service (device restart) by sending a traffic flood to upstream devices, aka Bug ID CSCva01813.
low complexity
cisco CWE-399
6.5
2016-07-28 CVE-2016-1465 Resource Management Errors vulnerability in Cisco Nx-Os
Cisco Nexus 1000v Application Virtual Switch (AVS) devices before 5.2(1)SV3(1.5i) allow remote attackers to cause a denial of service (ESXi hypervisor crash and purple screen) via a crafted Cisco Discovery Protocol packet that triggers an out-of-bounds memory access, aka Bug ID CSCuw57985.
low complexity
cisco CWE-399
6.5
2016-07-28 CVE-2016-1463 Improper Input Validation vulnerability in Cisco Firesight System Software
Cisco FireSIGHT System Software 5.3.0, 5.3.1, 5.4.0, 6.0, and 6.0.1 allows remote attackers to bypass Snort rules via crafted parameters in the header of an HTTP packet, aka Bug ID CSCuz20737.
network
low complexity
cisco CWE-20
7.5
2016-07-28 CVE-2016-1462 Cross-site Scripting vulnerability in Cisco Prime Service Catalog 11.0Base
Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Prime Service Catalog (PSC) 11.0 allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCuz63795.
network
low complexity
cisco CWE-79
6.1
2016-07-28 CVE-2016-1460 Resource Management Errors vulnerability in Cisco Wireless LAN Controller Software 7.4.121.0/8.0.0.30220.385
Cisco Wireless LAN Controller (WLC) devices 7.4(121.0) and 8.0(0.30220.385) allow remote attackers to cause a denial of service via crafted wireless management frames, aka Bug ID CSCun92979.
low complexity
cisco CWE-399
6.5
2016-07-28 CVE-2016-1374 Improper Input Validation vulnerability in Cisco Unified Computing System Performance Manager
The web framework in Cisco Unified Computing System (UCS) Performance Manager 2.0.0 and earlier allows remote authenticated users to execute arbitrary commands via crafted parameters in a GET request, aka Bug ID CSCuy07827.
network
low complexity
cisco CWE-20
8.8
2016-07-26 CVE-2016-3992 Improper Access Control vulnerability in multiple products
cronic before 3 allows local users to write to arbitrary files via a symlink attack on a (1) cronic.out.$$, (2) cronic.err.$$, or (3) cronic.trace.$$ file in /tmp.
local
low complexity
cronic-project debian opensuse CWE-284
6.2
2016-07-26 CVE-2015-5738 Information Exposure vulnerability in multiple products
The RSA-CRT implementation in the Cavium Software Development Kit (SDK) 2.x, when used on OCTEON II CN6xxx Hardware on Linux to support TLS with Perfect Forward Secrecy (PFS), makes it easier for remote attackers to obtain private RSA keys by conducting a Lenstra side-channel attack.
network
low complexity
marvell f5 CWE-200
7.5
2016-07-26 CVE-2016-6152 CA eHealth 6.2.x and 6.3.x before 6.3.2.13 allows remote authenticated users to cause a denial of service or possibly execute arbitrary commands via unspecified vectors.
network
low complexity
ca broadcom
8.8
2016-07-26 CVE-2016-6151 Unspecified vulnerability in CA Ehealth 6.2/6.2.1/6.2.2
CA eHealth 6.2.x allows remote authenticated users to cause a denial of service or possibly execute arbitrary commands via unspecified vectors.
network
low complexity
ca
8.8