Vulnerabilities > Cisco > IOS XR > Medium

DATE CVE VULNERABILITY TITLE RISK
2014-05-20 CVE-2014-3270 Improper Input Validation vulnerability in Cisco IOS XR
The DHCPv6 implementation in Cisco IOS XR allows remote attackers to cause a denial of service (process hang) via a malformed packet, aka Bug ID CSCul80924.
network
low complexity
cisco CWE-20
5.0
2014-04-05 CVE-2014-2144 Improper Input Validation vulnerability in Cisco IOS XR
Cisco IOS XR does not properly throttle ICMPv6 redirect packets, which allows remote attackers to cause a denial of service (IPv4 and IPv6 transit outage) via crafted redirect messages, aka Bug ID CSCum14266.
low complexity
cisco CWE-20
6.1
2013-11-29 CVE-2013-6700 Improper Input Validation vulnerability in Cisco IOS XR
The SNMP module in Cisco IOS XR allows remote attackers to cause a denial of service (process reload) via a request for an unspecified MIB, aka Bug ID CSCuh43144.
network
low complexity
cisco CWE-20
5.0
2013-11-08 CVE-2013-5565 Buffer Errors vulnerability in Cisco IOS XR 5.1.0
The OSPFv3 functionality in Cisco IOS XR 5.1 allows remote attackers to cause a denial of service (process crash) via a malformed LSA Type-1 packet, aka Bug ID CSCuj82176.
network
cisco CWE-119
4.3
2013-09-27 CVE-2013-5498 Improper Input Validation vulnerability in Cisco IOS XR
The PPTP-ALG component in CRS Carrier Grade Services Engine (CGSE) and ASR 9000 Integrated Service Module (ISM) in Cisco IOS XR allows remote attackers to cause a denial of service (module reset) via crafted packet streams, aka Bug ID CSCue91963.
network
low complexity
cisco CWE-20
5.0
2013-08-30 CVE-2013-3470 Improper Input Validation vulnerability in Cisco IOS XR
The RIP process in Cisco IOS XR allows remote attackers to cause a denial of service (process crash) via a crafted version-2 RIP packet, aka Bug ID CSCue46731.
network
low complexity
cisco CWE-20
5.0
2013-08-13 CVE-2013-3464 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cisco IOS XR
Cisco IOS XR allows local users to cause a denial of service (Silicon Packet Processor memory corruption, improper mutex handling, and device reload) by starting an outbound flood of large ICMP Echo Request packets and stopping this with a CTRL-C sequence, aka Bug ID CSCui60347.
local
low complexity
cisco CWE-119
4.6
2013-05-23 CVE-2013-1204 Resource Management Errors vulnerability in Cisco IOS XR
Memory leak in the SNMP process in Cisco IOS XR allows remote attackers to cause a denial of service (memory consumption or process reload) by sending many port-162 UDP packets, aka Bug ID CSCug80345.
network
low complexity
cisco CWE-399
5.0
2013-05-03 CVE-2013-1234 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cisco IOS XR
The SNMP module in Cisco IOS XR allows remote authenticated users to cause a denial of service (process restart) via crafted SNMP packets, aka Bug ID CSCue69472.
network
low complexity
cisco CWE-119
4.0
2013-04-29 CVE-2013-1216 Information Exposure vulnerability in Cisco IOS XR
Memory leak in the SNMP module in Cisco IOS XR allows remote authenticated users to cause a denial of service (memory consumption and process restart) via crafted SNMP packets, aka Bug ID CSCue31546.
network
low complexity
cisco CWE-200
4.0