Vulnerabilities > Cisco > IOS XR

DATE CVE VULNERABILITY TITLE RISK
2013-04-29 CVE-2013-1216 Information Exposure vulnerability in Cisco IOS XR
Memory leak in the SNMP module in Cisco IOS XR allows remote authenticated users to cause a denial of service (memory consumption and process restart) via crafted SNMP packets, aka Bug ID CSCue31546.
network
low complexity
cisco CWE-200
4.0
2013-03-26 CVE-2013-1162 Improper Input Validation vulnerability in Cisco IOS XR
The traffic engineering (TE) processing subsystem in Cisco IOS XR allows remote attackers to cause a denial of service (process restart) via crafted TE packets, aka Bug ID CSCue04000.
network
low complexity
cisco CWE-20
5.0
2012-09-27 CVE-2012-4617 Improper Input Validation vulnerability in Cisco Ios, IOS XE and IOS XR
The BGP implementation in Cisco IOS 15.2, IOS XE 3.5.xS before 3.5.2S, and IOS XR 4.1.0 through 4.2.2 allows remote attackers to cause a denial of service (multiple connection resets) by leveraging a peer relationship and sending a malformed attribute, aka Bug IDs CSCtt35379, CSCty58300, CSCtz63248, and CSCtz62914.
network
cisco CWE-20
7.1
2012-05-31 CVE-2012-2488 Improper Input Validation vulnerability in Cisco products
Cisco IOS XR before 4.2.1 on ASR 9000 series devices and CRS series devices allows remote attackers to cause a denial of service (packet transmission outage) via a crafted packet, aka Bug IDs CSCty94537 and CSCtz62593.
network
low complexity
cisco CWE-20
7.8
2012-05-02 CVE-2011-3295 Improper Input Validation vulnerability in Cisco IOS XR
The NETIO and IPV4_IO processes in Cisco IOS XR 3.8 through 4.1, as used in Cisco Carrier Routing System and other products, allow remote attackers to cause a denial of service (CPU consumption) via crafted network traffic, aka Bug ID CSCti59888.
network
low complexity
cisco CWE-20
7.8
2011-07-28 CVE-2011-2549 Denial of Service vulnerability in Cisco ASR 9006 Router, ASR 9010 Router and IOS XR
Unspecified vulnerability in Cisco IOS XR 4.1.x before 4.1.1 on Cisco Aggregation Services Routers (ASR) 9000 series devices allows remote attackers to cause a denial of service (line-card reload) via an IPv4 packet, aka Bug ID CSCtr26695.
network
low complexity
cisco
7.8
2011-05-31 CVE-2011-1651 Resource Management Errors vulnerability in Cisco IOS XR
Cisco IOS XR 3.9.x and 4.0.x before 4.0.3 and 4.1.x before 4.1.1, when an SPA interface processor is installed, allows remote attackers to cause a denial of service (device reload) via a crafted IPv4 packet, aka Bug ID CSCto45095.
network
low complexity
cisco CWE-399
7.8
2011-05-31 CVE-2011-0949 Resource Management Errors vulnerability in Cisco IOS XR
Cisco IOS XR 3.6.x, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 does not properly remove sshd_lock files from /tmp/, which allows remote attackers to cause a denial of service (disk consumption) by making many SSHv1 connections, aka Bug ID CSCtd64417.
network
low complexity
cisco CWE-399
7.8
2011-05-31 CVE-2011-0943 Resource Management Errors vulnerability in Cisco IOS XR 3.8.3/3.8.4/3.9.1
Cisco IOS XR 3.8.3, 3.8.4, and 3.9.1 allows remote attackers to cause a denial of service (NetIO process restart or device reload) via a crafted IPv4 packet, aka Bug ID CSCth44147.
network
low complexity
cisco CWE-399
7.8
2010-08-30 CVE-2010-3035 Improper Input Validation vulnerability in Cisco IOS XR
Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in August 2010 with attribute type code 99, aka Bug ID CSCti62211.
network
low complexity
cisco CWE-20
5.0