Vulnerabilities > Cisco > IOS > 12.3za

DATE CVE VULNERABILITY TITLE RISK
2010-03-25 CVE-2010-0580 Unspecified vulnerability in Cisco IOS
Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message, aka Bug ID CSCsz48680, the "SIP Message Processing Arbitrary Code Execution Vulnerability."
network
low complexity
cisco
critical
10.0
2010-03-25 CVE-2010-0579 Unspecified vulnerability in Cisco IOS
The SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to cause a denial of service (device reload) via a malformed SIP message, aka Bug ID CSCtb93416, the "SIP Message Handling Denial of Service Vulnerability."
network
low complexity
cisco
7.8
2010-03-25 CVE-2010-0578 Cryptographic Issues vulnerability in Cisco IOS
The IKE implementation in Cisco IOS 12.2 through 12.4 on Cisco 7200 and 7301 routers with VAM2+ allows remote attackers to cause a denial of service (device reload) via a malformed IKE packet, aka Bug ID CSCtb13491.
network
low complexity
cisco CWE-310
7.8
2010-03-25 CVE-2010-0577 Resource Management Errors vulnerability in Cisco IOS
Cisco IOS 12.2 through 12.4, when certain PMTUD, SNAT, or window-size configurations are used, allows remote attackers to cause a denial of service (infinite loop, and device reload or hang) via a TCP segment with crafted options, aka Bug ID CSCsz75186.
network
cisco CWE-399
7.1
2010-03-25 CVE-2010-0576 Denial of Service vulnerability in Cisco IOS Multiprotocol Label Switching (MPLS) Malformed Packet
Unspecified vulnerability in Cisco IOS 12.0 through 12.4, IOS XE 2.1.x through 2.3.x before 2.3.2, and IOS XR 3.2.x through 3.4.3, when Multiprotocol Label Switching (MPLS) and Label Distribution Protocol (LDP) are enabled, allows remote attackers to cause a denial of service (device reload or process restart) via a crafted LDP packet, aka Bug IDs CSCsz45567 and CSCsj25893.
network
low complexity
cisco
7.8
2009-09-28 CVE-2009-2866 Denial of Service vulnerability in Cisco IOS H.323
Unspecified vulnerability in Cisco IOS 12.2 through 12.4 allows remote attackers to cause a denial of service (device reload) via a crafted H.323 packet, aka Bug ID CSCsz38104.
network
low complexity
cisco
7.8
2009-08-27 CVE-2009-2051 Unspecified vulnerability in Cisco IOS and Unified Communications Manager
Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), and 7.x before 7.1(2) allow remote attackers to cause a denial of service (device reload or voice-services outage) via a malformed SIP INVITE message that triggers an improper call to the sipSafeStrlen function, aka Bug IDs CSCsz40392 and CSCsz43987.
network
low complexity
cisco
7.8
2009-01-16 CVE-2008-3821 Cross-Site Scripting vulnerability in Cisco IOS
Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 11.0 through 12.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the ping program or (2) unspecified other aspects of the URI.
network
cisco CWE-79
4.3
2008-09-26 CVE-2008-3809 Unspecified vulnerability in Cisco IOS
Cisco IOS 12.0 through 12.4 on Gigabit Switch Router (GSR) devices (aka 12000 Series routers) allows remote attackers to cause a denial of service (device crash) via a malformed Protocol Independent Multicast (PIM) packet.
network
cisco
7.1
2008-09-26 CVE-2008-3808 Unspecified vulnerability in Cisco IOS
Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via a crafted Protocol Independent Multicast (PIM) packet.
network
low complexity
cisco
7.8