Vulnerabilities > Cisco > IOS XR > 3.7.0

DATE CVE VULNERABILITY TITLE RISK
2014-07-18 CVE-2014-3321 Improper Input Validation vulnerability in Cisco products
Cisco IOS XR 4.3.4 and earlier on ASR 9000 devices, when bridge-group virtual interface (BVI) routing is enabled, allows remote attackers to cause a denial of service (chip and card hangs) via a series of crafted MPLS packets, aka Bug ID CSCuo91149.
5.7
2012-05-31 CVE-2012-2488 Improper Input Validation vulnerability in Cisco products
Cisco IOS XR before 4.2.1 on ASR 9000 series devices and CRS series devices allows remote attackers to cause a denial of service (packet transmission outage) via a crafted packet, aka Bug IDs CSCty94537 and CSCtz62593.
network
low complexity
cisco CWE-20
7.8
2010-08-30 CVE-2010-3035 Improper Input Validation vulnerability in Cisco IOS XR
Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in August 2010 with attribute type code 99, aka Bug ID CSCti62211.
network
low complexity
cisco CWE-20
5.0
2010-01-21 CVE-2010-0137 Remote Denial of Service vulnerability in Cisco IOS XR SSH Protocol Implementation
Unspecified vulnerability in the sshd_child_handler process in the SSH server in Cisco IOS XR 3.4.1 through 3.7.0 allows remote attackers to cause a denial of service (process crash and memory consumption) via a crafted SSH2 packet, aka Bug ID CSCsu10574.
network
low complexity
cisco
7.8
2009-08-21 CVE-2009-2056 Permissions, Privileges, and Access Controls vulnerability in Cisco IOS XR
Cisco IOS XR 3.8.1 and earlier allows remote authenticated users to cause a denial of service (process crash) via vectors involving a BGP UPDATE message with many AS numbers prepended to the AS path.
network
low complexity
cisco CWE-264
3.3
2009-08-21 CVE-2009-1154 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cisco IOS XR
Cisco IOS XR 3.8.1 and earlier allows remote attackers to cause a denial of service (process crash) via a long BGP UPDATE message, as demonstrated by a message with many AS numbers in the AS Path Attribute.
network
low complexity
cisco CWE-119
3.3
2009-08-19 CVE-2009-2055 Improper Input Validation vulnerability in Cisco IOS XR
Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.
network
cisco CWE-20
4.3