Vulnerabilities > Cisco > IOS > 12.4.3g.ja

DATE CVE VULNERABILITY TITLE RISK
2011-01-07 CVE-2010-4683 Missing Release of Resource After Effective Lifetime vulnerability in Cisco IOS
Memory leak in Cisco IOS before 15.0(1)XA5 might allow remote attackers to cause a denial of service (memory consumption) by sending a crafted SIP REGISTER message over UDP, aka Bug ID CSCtg41733.
network
low complexity
cisco CWE-772
7.8
2011-01-07 CVE-2009-5040 Resource Management Errors vulnerability in Cisco IOS
CallManager Express (CME) on Cisco IOS before 15.0(1)XA allows remote authenticated users to cause a denial of service (device crash) by using an extension mobility (EM) phone to interact with the menu for SNR number changes, aka Bug ID CSCta63555.
network
low complexity
cisco CWE-399
6.8
2011-01-07 CVE-2009-5039 Missing Release of Resource After Effective Lifetime vulnerability in Cisco IOS
Memory leak in the gk_circuit_info_do_in_acf function in the H.323 implementation in Cisco IOS before 15.0(1)XA allows remote attackers to cause a denial of service (memory consumption) via a large number of calls over a long duration, as demonstrated by InterZone Clear Token (IZCT) test traffic, aka Bug ID CSCsz72535.
network
low complexity
cisco CWE-772
5.0
2011-01-07 CVE-2009-5038 Improper Input Validation vulnerability in Cisco IOS
Cisco IOS before 15.0(1)XA does not properly handle IRC traffic during a specific time period after an initial reload, which allows remote attackers to cause a denial of service (device reload) via an attempted connection to a certain IRC server, related to a "corrupted magic value," aka Bug ID CSCso05336.
network
low complexity
cisco CWE-20
7.8
2011-01-07 CVE-2010-4671 Resource Exhaustion vulnerability in Cisco IOS
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS before 15.0(1)XA5 allows remote attackers to cause a denial of service (CPU consumption and device hang) by sending many Router Advertisement (RA) messages with different source addresses, as demonstrated by the flood_router6 program in the thc-ipv6 package, aka Bug ID CSCti33534.
network
low complexity
cisco CWE-400
7.8