Vulnerabilities > Cisco > IOS > 12.4.2.mr1

DATE CVE VULNERABILITY TITLE RISK
2015-01-28 CVE-2015-0586 Resource Management Errors vulnerability in Cisco IOS
The Network-Based Application Recognition (NBAR) protocol implementation in Cisco IOS 15.3(100)M and earlier on Cisco 2900 Integrated Services Router (aka Cisco Internet Router) devices allows remote attackers to cause a denial of service (NBAR process hang) via IPv4 packets, aka Bug ID CSCuo73682.
network
low complexity
cisco CWE-399
7.8
2014-05-16 CVE-2014-3262 Improper Input Validation vulnerability in Cisco IOS XE
The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.3(3)S and earlier and IOS XE does not properly validate parameters in ITR control messages, which allows remote attackers to cause a denial of service (CEF outage and packet drops) via malformed messages, aka Bug ID CSCun73782.
network
cisco CWE-20
4.3
2014-04-24 CVE-2012-3946 Permissions, Privileges, and Access Controls vulnerability in Cisco IOS
Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an unspecified scenario in which expected packet drops do not occur for "a small percentage" of the packets, aka Bug ID CSCty73682.
network
low complexity
cisco CWE-264
5.0
2014-04-23 CVE-2012-5427 Improper Input Validation vulnerability in Cisco IOS
Cisco IOS Unified Border Element (CUBE) in Cisco IOS before 15.3(2)T allows remote authenticated users to cause a denial of service (input queue wedge) via a crafted series of RTCP packets, aka Bug ID CSCuc42518.
network
low complexity
cisco CWE-20
4.0
2014-04-23 CVE-2012-5422 Denial-Of-Service vulnerability in Cisco IOS
Unspecified vulnerability in Cisco IOS before 15.3(2)T on AS5400 devices allows remote authenticated users to cause a denial of service (spurious errors) via unknown vectors, aka Bug ID CSCub61009.
network
low complexity
cisco
6.8
2014-04-23 CVE-2012-5044 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cisco IOS
Cisco IOS before 15.3(1)T, when media flow-around is not used, allows remote attackers to cause a denial of service (media loops and stack memory corruption) via VoIP traffic, aka Bug ID CSCub45809.
network
high complexity
cisco CWE-119
5.4
2014-04-23 CVE-2012-5037 Permissions, Privileges, and Access Controls vulnerability in Cisco IOS
The ACL implementation in Cisco IOS before 15.1(1)SY on Catalyst 6500 and 7600 devices allows local users to cause a denial of service (device reload) via a "no object-group" command followed by an object-group command, aka Bug ID CSCts16133.
local
low complexity
cisco CWE-264
4.6
2014-04-23 CVE-2012-5032 Improper Authentication vulnerability in Cisco IOS
The Flex-VPN load-balancing feature in the ipsec-ikev2 implementation in Cisco IOS before 15.1(1)SY3 does not require authentication, which allows remote attackers to trigger the forwarding of VPN traffic to an attacker-controlled destination, or the discarding of this traffic, by arranging for an arbitrary device to become a cluster member, aka Bug ID CSCub93641.
network
low complexity
cisco CWE-287
6.4
2014-04-23 CVE-2012-5017 Improper Input Validation vulnerability in Cisco products
Cisco IOS before 15.1(1)SY1 allows remote authenticated users to cause a denial of service (device reload) by establishing a VPN session and then sending malformed IKEv2 packets, aka Bug ID CSCub39268.
network
low complexity
cisco CWE-20
6.8
2014-04-23 CVE-2012-5014 Denial-Of-Service vulnerability in IOS
Cisco IOS before 15.1(2)SY allows remote authenticated users to cause a denial of service (device crash) by establishing an SSH session from a client and then placing this client into a (1) slow or (2) idle state, aka Bug ID CSCto87436.
network
cisco
6.3