Vulnerabilities > Cisco > IOS > 12.1.5a.e1

DATE CVE VULNERABILITY TITLE RISK
2013-11-18 CVE-2013-6686 Improper Input Validation vulnerability in Cisco IOS
The SSL VPN implementation in Cisco IOS 15.3(1)T2 and earlier allows remote authenticated users to cause a denial of service (interface queue wedge) via crafted DTLS packets in an SSL session, aka Bug IDs CSCuh97409 and CSCud90568.
network
low complexity
cisco CWE-20
6.8
2013-11-13 CVE-2013-5552 Permissions, Privileges, and Access Controls vulnerability in Cisco IOS
Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows remote attackers to bypass intended access restrictions via a crafted series of packets, aka Bug ID CSCug90143.
network
low complexity
cisco CWE-264
6.4
2011-10-22 CVE-2011-2059 Information Exposure vulnerability in Cisco IOS
The ipv6 component in Cisco IOS before 15.1(4)M1.3 allows remote attackers to conduct fingerprinting attacks and obtain potentially sensitive information about the presence of the IOS operating system via an ICMPv6 Echo Request packet containing a Hop-by-Hop (HBH) extension header (EH) with a 0x0c01050c value in the PadN option data, aka Bug ID CSCtq02219.
network
low complexity
cisco CWE-200
5.0
2011-10-03 CVE-2011-3279 Unspecified vulnerability in Cisco IOS and IOS XE
The provider-edge MPLS NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload) via a malformed SIP packet to UDP port 5060, aka Bug ID CSCti98219.
network
low complexity
cisco
7.8
2011-10-03 CVE-2011-0946 Unspecified vulnerability in Cisco IOS and IOS XE
The NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload or hang) via malformed NetMeeting Directory (aka Internet Locator Service or ILS) LDAP traffic, aka Bug ID CSCtd10712.
network
low complexity
cisco
7.8
2011-01-07 CVE-2010-4687 Improper Input Validation vulnerability in Cisco IOS
STCAPP (aka the SCCP telephony control application) on Cisco IOS before 15.0(1)XA1 does not properly handle multiple calls to a shared line, which allows remote attackers to cause a denial of service (port hang) by simultaneously ending two calls that were controlled by CallManager Express (CME), aka Bug ID CSCtd42552.
network
low complexity
cisco CWE-20
5.0
2011-01-07 CVE-2010-4686 Resource Exhaustion vulnerability in Cisco IOS
CallManager Express (CME) on Cisco IOS before 15.0(1)XA1 does not properly handle SIP TRUNK traffic that contains rate bursts and a "peculiar" request size, which allows remote attackers to cause a denial of service (memory consumption) by sending this traffic over a long duration, aka Bug ID CSCtb47950.
network
low complexity
cisco CWE-400
7.8
2011-01-07 CVE-2010-4685 Improper Certificate Validation vulnerability in Cisco IOS
Cisco IOS before 15.0(1)XA1 does not clear the public key cache upon a change to a certificate map, which allows remote authenticated users to bypass a certificate ban by connecting with a banned certificate that had previously been valid, aka Bug ID CSCta79031.
network
low complexity
cisco CWE-295
4.0
2011-01-07 CVE-2010-4684 Improper Input Validation vulnerability in Cisco IOS
Cisco IOS before 15.0(1)XA1, when certain TFTP debugging is enabled, allows remote attackers to cause a denial of service (device crash) via a TFTP copy over IPv6, aka Bug ID CSCtb28877.
network
cisco CWE-20
7.1
2011-01-07 CVE-2010-4683 Missing Release of Resource After Effective Lifetime vulnerability in Cisco IOS
Memory leak in Cisco IOS before 15.0(1)XA5 might allow remote attackers to cause a denial of service (memory consumption) by sending a crafted SIP REGISTER message over UDP, aka Bug ID CSCtg41733.
network
low complexity
cisco CWE-772
7.8