Vulnerabilities > Cisco > IOS > 15.2.4.m4

DATE CVE VULNERABILITY TITLE RISK
2014-04-24 CVE-2012-3946 Permissions, Privileges, and Access Controls vulnerability in Cisco IOS
Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an unspecified scenario in which expected packet drops do not occur for "a small percentage" of the packets, aka Bug ID CSCty73682.
network
low complexity
cisco CWE-264
5.0
2014-04-23 CVE-2012-5427 Improper Input Validation vulnerability in Cisco IOS
Cisco IOS Unified Border Element (CUBE) in Cisco IOS before 15.3(2)T allows remote authenticated users to cause a denial of service (input queue wedge) via a crafted series of RTCP packets, aka Bug ID CSCuc42518.
network
low complexity
cisco CWE-20
4.0
2014-04-23 CVE-2012-5422 Denial-Of-Service vulnerability in Cisco IOS
Unspecified vulnerability in Cisco IOS before 15.3(2)T on AS5400 devices allows remote authenticated users to cause a denial of service (spurious errors) via unknown vectors, aka Bug ID CSCub61009.
network
low complexity
cisco
6.8
2014-04-23 CVE-2012-4651 Numeric Errors vulnerability in Cisco IOS
Cisco IOS before 15.3(2)T, when scansafe is enabled, allows remote attackers to cause a denial of service (latency) via SYN packets that are not accompanied by SYN-ACK packets from the Scan Safe Tower, aka Bug ID CSCub85451.
network
cisco CWE-189
4.3
2014-04-23 CVE-2012-3918 Denial-Of-Service vulnerability in Cisco IOS
Cisco IOS before 15.3(1)T on Cisco 2900 devices, when a VWIC2-2MFT-T1/E1 card is configured for TDM/HDLC mode, allows remote attackers to cause a denial of service (serial-interface outage) via certain Frame Relay traffic, aka Bug ID CSCub13317.
network
cisco
4.3
2014-04-04 CVE-2014-2143 Denial of Service vulnerability in Cisco IOS XE
The IKE implementation in Cisco IOS 15.4(1)T and earlier and IOS XE allows remote attackers to cause a denial of service (security-association drop) via crafted Main Mode packets, aka Bug ID CSCun31021.
network
low complexity
cisco
5.0
2013-11-22 CVE-2013-6693 Buffer Errors vulnerability in Cisco IOS
The MLDP implementation in Cisco IOS 15.3(3)S and earlier on 7600 routers, when many VRFs are configured, allows remote attackers to cause a denial of service (chunk corruption and device reload) by establishing many multicast flows, aka Bug ID CSCue22345.
network
high complexity
cisco CWE-119
5.4
2013-11-18 CVE-2013-6686 Improper Input Validation vulnerability in Cisco IOS
The SSL VPN implementation in Cisco IOS 15.3(1)T2 and earlier allows remote authenticated users to cause a denial of service (interface queue wedge) via crafted DTLS packets in an SSL session, aka Bug IDs CSCuh97409 and CSCud90568.
network
low complexity
cisco CWE-20
6.8