Vulnerabilities > Cisco > IOS > 12.2sre

DATE CVE VULNERABILITY TITLE RISK
2011-10-03 CVE-2011-3279 Unspecified vulnerability in Cisco IOS and IOS XE
The provider-edge MPLS NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload) via a malformed SIP packet to UDP port 5060, aka Bug ID CSCti98219.
network
low complexity
cisco
7.8
2011-10-03 CVE-2011-3278 Unspecified vulnerability in Cisco IOS and IOS XE
Unspecified vulnerability in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload) by sending crafted SIP packets to UDP port 5060, aka Bug ID CSCti48483.
network
low complexity
cisco
7.8
2011-10-03 CVE-2011-3277 Unspecified vulnerability in Cisco IOS and IOS XE
Unspecified vulnerability in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload) by sending crafted H.323 packets to TCP port 1720, aka Bug ID CSCth11006.
network
low complexity
cisco
7.8
2011-10-03 CVE-2011-3276 Unspecified vulnerability in Cisco IOS and IOS XE
Unspecified vulnerability in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload or hang) by sending crafted SIP packets to TCP port 5060, aka Bug ID CSCso02147.
network
low complexity
cisco
7.8
2011-10-03 CVE-2011-3274 Unspecified vulnerability in Cisco IOS and IOS XE
Unspecified vulnerability in Cisco IOS 12.2SRE before 12.2(33)SRE4, 15.0, and 15.1, and IOS XE 2.1.x through 3.3.x, when an MPLS domain is configured, allows remote attackers to cause a denial of service (device crash) via a crafted IPv6 packet, related to an expired MPLS TTL, aka Bug ID CSCto07919.
low complexity
cisco
6.1
2011-10-03 CVE-2011-0946 Unspecified vulnerability in Cisco IOS and IOS XE
The NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload or hang) via malformed NetMeeting Directory (aka Internet Locator Service or ILS) LDAP traffic, aka Bug ID CSCtd10712.
network
low complexity
cisco
7.8
2011-10-03 CVE-2011-0945 Resource Management Errors vulnerability in Cisco IOS and IOS XE
Memory leak in the Data-link switching (aka DLSw) feature in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xS before 3.1.3S and 3.2.xS before 3.2.1S, when implemented over Fast Sequence Transport (FST), allows remote attackers to cause a denial of service (memory consumption and device reload or hang) via a crafted IP protocol 91 packet, aka Bug ID CSCth69364.
network
low complexity
cisco CWE-399
7.8
2011-01-07 CVE-2010-4687 Improper Input Validation vulnerability in Cisco IOS
STCAPP (aka the SCCP telephony control application) on Cisco IOS before 15.0(1)XA1 does not properly handle multiple calls to a shared line, which allows remote attackers to cause a denial of service (port hang) by simultaneously ending two calls that were controlled by CallManager Express (CME), aka Bug ID CSCtd42552.
network
low complexity
cisco CWE-20
5.0
2011-01-07 CVE-2010-4686 Resource Exhaustion vulnerability in Cisco IOS
CallManager Express (CME) on Cisco IOS before 15.0(1)XA1 does not properly handle SIP TRUNK traffic that contains rate bursts and a "peculiar" request size, which allows remote attackers to cause a denial of service (memory consumption) by sending this traffic over a long duration, aka Bug ID CSCtb47950.
network
low complexity
cisco CWE-400
7.8
2011-01-07 CVE-2010-4685 Improper Certificate Validation vulnerability in Cisco IOS
Cisco IOS before 15.0(1)XA1 does not clear the public key cache upon a change to a certificate map, which allows remote authenticated users to bypass a certificate ban by connecting with a banned certificate that had previously been valid, aka Bug ID CSCta79031.
network
low complexity
cisco CWE-295
4.0