Vulnerabilities > Cisco > IOS > 12.4xd

DATE CVE VULNERABILITY TITLE RISK
2009-01-16 CVE-2008-3821 Cross-Site Scripting vulnerability in Cisco IOS
Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 11.0 through 12.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the ping program or (2) unspecified other aspects of the URI.
network
cisco CWE-79
4.3
2008-09-26 CVE-2008-3808 Unspecified vulnerability in Cisco IOS
Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via a crafted Protocol Independent Multicast (PIM) packet.
network
low complexity
cisco
7.8
2008-09-26 CVE-2008-3802 Unspecified vulnerability in Cisco IOS
Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4, when VoIP is configured, allows remote attackers to cause a denial of service (device reload) via unspecified valid SIP messages, aka Cisco bug ID CSCsk42759, a different vulnerability than CVE-2008-3800 and CVE-2008-3801.
network
cisco
7.1
2007-10-12 CVE-2007-5381 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cisco IOS
Stack-based buffer overflow in the Line Printer Daemon (LPD) in Cisco IOS before 12.2(18)SXF11, 12.4(16a), and 12.4(2)T6 allow remote attackers to execute arbitrary code by setting a long hostname on the target system, then causing an error message to be printed, as demonstrated by a telnet session to the LPD from a source port other than 515.
network
cisco CWE-119
critical
9.3
2007-05-10 CVE-2007-2587 Multiple vulnerability in Cisco IOS FTP Server
The IOS FTP Server in Cisco IOS 11.3 through 12.4 allows remote authenticated users to cause a denial of service (IOS reload) via unspecified vectors involving transferring files (aka bug ID CSCse29244).
network
cisco
6.3
2007-02-01 CVE-2007-0648 Remote Denial Of Service vulnerability in Cisco IOS SIP Packet Handling
Cisco IOS after 12.3(14)T, 12.3(8)YC1, 12.3(8)YG, and 12.4, with voice support and without Session Initiated Protocol (SIP) configured, allows remote attackers to cause a denial of service (crash) by sending a crafted packet to port 5060/UDP.
network
low complexity
cisco
7.8