Vulnerabilities > Cisco > IOS > 12.4yb

DATE CVE VULNERABILITY TITLE RISK
2012-09-27 CVE-2012-4623 Improper Input Validation vulnerability in Cisco IOS and IOS XE
The DHCPv6 server in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x, 3.1.xS before 3.1.4S, 3.1.xSG and 3.2.xSG before 3.2.5SG, 3.2.xS, 3.2.xXO, 3.3.xS, and 3.3.xSG before 3.3.1SG allows remote attackers to cause a denial of service (device reload) via a malformed DHCPv6 packet, aka Bug ID CSCto57723.
network
low complexity
cisco CWE-20
7.8
2012-09-27 CVE-2012-3950 Resource Management Errors vulnerability in Cisco IOS
The Intrusion Prevention System (IPS) feature in Cisco IOS 12.3 through 12.4 and 15.0 through 15.2, in certain configurations of enabled categories and missing signatures, allows remote attackers to cause a denial of service (device reload) via DNS packets, aka Bug ID CSCtw55976.
network
cisco CWE-399
7.1
2012-08-06 CVE-2012-1350 Unspecified vulnerability in Cisco products
Cisco IOS 12.3 and 12.4 on Aironet access points allows remote attackers to cause a denial of service (radio-interface input-queue hang) via IAPP 0x3281 packets, aka Bug ID CSCtc12426.
network
low complexity
cisco
7.8
2011-10-22 CVE-2011-2059 Information Exposure vulnerability in Cisco IOS
The ipv6 component in Cisco IOS before 15.1(4)M1.3 allows remote attackers to conduct fingerprinting attacks and obtain potentially sensitive information about the presence of the IOS operating system via an ICMPv6 Echo Request packet containing a Hop-by-Hop (HBH) extension header (EH) with a 0x0c01050c value in the PadN option data, aka Bug ID CSCtq02219.
network
low complexity
cisco CWE-200
5.0
2011-10-03 CVE-2011-3280 Resource Management Errors vulnerability in Cisco IOS and IOS XE
Memory leak in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (memory consumption or device reload) by sending crafted SIP packets to UDP port 5060, aka Bug ID CSCtj04672.
network
low complexity
cisco CWE-399
7.8
2011-10-03 CVE-2011-3278 Unspecified vulnerability in Cisco IOS and IOS XE
Unspecified vulnerability in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload) by sending crafted SIP packets to UDP port 5060, aka Bug ID CSCti48483.
network
low complexity
cisco
7.8
2011-10-03 CVE-2011-3277 Unspecified vulnerability in Cisco IOS and IOS XE
Unspecified vulnerability in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload) by sending crafted H.323 packets to TCP port 1720, aka Bug ID CSCth11006.
network
low complexity
cisco
7.8
2011-10-03 CVE-2011-3276 Unspecified vulnerability in Cisco IOS and IOS XE
Unspecified vulnerability in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload or hang) by sending crafted SIP packets to TCP port 5060, aka Bug ID CSCso02147.
network
low complexity
cisco
7.8
2011-10-03 CVE-2011-0945 Resource Management Errors vulnerability in Cisco IOS and IOS XE
Memory leak in the Data-link switching (aka DLSw) feature in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xS before 3.1.3S and 3.2.xS before 3.2.1S, when implemented over Fast Sequence Transport (FST), allows remote attackers to cause a denial of service (memory consumption and device reload or hang) via a crafted IP protocol 91 packet, aka Bug ID CSCth69364.
network
low complexity
cisco CWE-399
7.8
2011-01-07 CVE-2010-4687 Improper Input Validation vulnerability in Cisco IOS
STCAPP (aka the SCCP telephony control application) on Cisco IOS before 15.0(1)XA1 does not properly handle multiple calls to a shared line, which allows remote attackers to cause a denial of service (port hang) by simultaneously ending two calls that were controlled by CallManager Express (CME), aka Bug ID CSCtd42552.
network
low complexity
cisco CWE-20
5.0