Vulnerabilities > Cisco > IOS > 15.0.2.eh

DATE CVE VULNERABILITY TITLE RISK
2014-03-21 CVE-2014-2124 Resource Management Errors vulnerability in Cisco IOS
Cisco IOS 15.1(2)SY3 and earlier, when used with Supervisor Engine 2T (aka Sup2T) on Catalyst 6500 devices, allows remote attackers to cause a denial of service (device crash) via crafted multicast packets, aka Bug ID CSCuf60783.
network
cisco CWE-399
7.1
2013-11-22 CVE-2013-6693 Buffer Errors vulnerability in Cisco IOS
The MLDP implementation in Cisco IOS 15.3(3)S and earlier on 7600 routers, when many VRFs are configured, allows remote attackers to cause a denial of service (chunk corruption and device reload) by establishing many multicast flows, aka Bug ID CSCue22345.
network
high complexity
cisco CWE-119
5.4
2013-11-18 CVE-2013-6686 Improper Input Validation vulnerability in Cisco IOS
The SSL VPN implementation in Cisco IOS 15.3(1)T2 and earlier allows remote authenticated users to cause a denial of service (interface queue wedge) via crafted DTLS packets in an SSL session, aka Bug IDs CSCuh97409 and CSCud90568.
network
low complexity
cisco CWE-20
6.8
2013-03-28 CVE-2013-1142 Race Condition vulnerability in Cisco IOS
Race condition in the VRF-aware NAT feature in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 allows remote attackers to cause a denial of service (memory consumption) via IPv4 packets, aka Bug IDs CSCtg47129 and CSCtz96745.
network
low complexity
cisco CWE-362
7.8
2011-10-22 CVE-2011-2059 Information Exposure vulnerability in Cisco IOS
The ipv6 component in Cisco IOS before 15.1(4)M1.3 allows remote attackers to conduct fingerprinting attacks and obtain potentially sensitive information about the presence of the IOS operating system via an ICMPv6 Echo Request packet containing a Hop-by-Hop (HBH) extension header (EH) with a 0x0c01050c value in the PadN option data, aka Bug ID CSCtq02219.
network
low complexity
cisco CWE-200
5.0
2011-10-03 CVE-2011-3279 Unspecified vulnerability in Cisco IOS and IOS XE
The provider-edge MPLS NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload) via a malformed SIP packet to UDP port 5060, aka Bug ID CSCti98219.
network
low complexity
cisco
7.8
2011-10-03 CVE-2011-0946 Unspecified vulnerability in Cisco IOS and IOS XE
The NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload or hang) via malformed NetMeeting Directory (aka Internet Locator Service or ILS) LDAP traffic, aka Bug ID CSCtd10712.
network
low complexity
cisco
7.8
2011-01-07 CVE-2009-5040 Resource Management Errors vulnerability in Cisco IOS
CallManager Express (CME) on Cisco IOS before 15.0(1)XA allows remote authenticated users to cause a denial of service (device crash) by using an extension mobility (EM) phone to interact with the menu for SNR number changes, aka Bug ID CSCta63555.
network
low complexity
cisco CWE-399
6.8
2009-08-27 CVE-2009-2051 Unspecified vulnerability in Cisco IOS and Unified Communications Manager
Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), and 7.x before 7.1(2) allow remote attackers to cause a denial of service (device reload or voice-services outage) via a malformed SIP INVITE message that triggers an improper call to the sipSafeStrlen function, aka Bug IDs CSCsz40392 and CSCsz43987.
network
low complexity
cisco
7.8