Vulnerabilities > Cisco > IOS > High

DATE CVE VULNERABILITY TITLE RISK
2013-03-28 CVE-2013-1148 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cisco IOS and IOS XE
The General Responder implementation in the IP Service Level Agreement (SLA) feature in Cisco IOS 15.2 and IOS XE 3.1.xS through 3.4.xS before 3.4.5S and 3.5.xS through 3.7.xS before 3.7.2S allows remote attackers to cause a denial of service (device reload) via crafted (1) IPv4 or (2) IPv6 IP SLA packets on UDP port 1167, aka Bug ID CSCuc72594.
network
low complexity
cisco CWE-119
7.8
2013-03-28 CVE-2013-1147 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cisco IOS
The Protocol Translation (PT) functionality in Cisco IOS 12.3 through 12.4 and 15.0 through 15.3, when one-step port-23 translation or a Telnet-to-PAD ruleset is configured, does not properly validate TCP connection information, which allows remote attackers to cause a denial of service (device reload) via an attempted connection to a PT resource, aka Bug ID CSCtz35999.
network
low complexity
cisco CWE-119
7.8
2013-03-28 CVE-2013-1146 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cisco IOS
The Smart Install client functionality in Cisco IOS 12.2 and 15.0 through 15.3 on Catalyst switches allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in Smart Install packets, aka Bug ID CSCub55790.
network
low complexity
cisco CWE-119
7.8
2013-03-28 CVE-2013-1145 Resource Management Errors vulnerability in Cisco IOS
Memory leak in Cisco IOS 12.2, 12.4, 15.0, and 15.1, when Zone-Based Policy Firewall SIP application layer gateway inspection is enabled, allows remote attackers to cause a denial of service (memory consumption or device reload) via malformed SIP messages, aka Bug ID CSCtl99174.
network
low complexity
cisco CWE-399
7.8
2013-03-28 CVE-2013-1144 Resource Management Errors vulnerability in Cisco IOS 15.1
Memory leak in the IKEv1 implementation in Cisco IOS 15.1 allows remote attackers to cause a denial of service (memory consumption) via unspecified (1) IPv4 or (2) IPv6 IKE packets, aka Bug ID CSCth81055.
network
low complexity
cisco CWE-399
7.8
2013-03-28 CVE-2013-1143 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cisco IOS and IOS XE
The RSVP protocol implementation in Cisco IOS 12.2 and 15.0 through 15.2 and IOS XE 3.1.xS through 3.4.xS before 3.4.5S and 3.5.xS through 3.7.xS before 3.7.2S, when MPLS-TE is enabled, allows remote attackers to cause a denial of service (incorrect memory access and device reload) via a traffic engineering PATH message in an RSVP packet, aka Bug ID CSCtg39957.
network
cisco CWE-119
7.1
2013-03-28 CVE-2013-1142 Race Condition vulnerability in Cisco IOS
Race condition in the VRF-aware NAT feature in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 allows remote attackers to cause a denial of service (memory consumption) via IPv4 packets, aka Bug IDs CSCtg47129 and CSCtz96745.
network
low complexity
cisco CWE-362
7.8
2012-09-27 CVE-2012-4623 Improper Input Validation vulnerability in Cisco IOS and IOS XE
The DHCPv6 server in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x, 3.1.xS before 3.1.4S, 3.1.xSG and 3.2.xSG before 3.2.5SG, 3.2.xS, 3.2.xXO, 3.3.xS, and 3.3.xSG before 3.3.1SG allows remote attackers to cause a denial of service (device reload) via a malformed DHCPv6 packet, aka Bug ID CSCto57723.
network
low complexity
cisco CWE-20
7.8
2012-09-27 CVE-2012-4621 Resource Management Errors vulnerability in Cisco IOS
The Device Sensor feature in Cisco IOS 15.0 through 15.2 allows remote attackers to cause a denial of service (device reload) via a DHCP packet, aka Bug ID CSCty96049.
network
low complexity
cisco CWE-399
7.8
2012-09-27 CVE-2012-4620 Resource Management Errors vulnerability in Cisco 10008 Router and IOS
Cisco IOS 12.2 and 15.0 through 15.2 on Cisco 10000 series routers, when a tunnel interface exists, allows remote attackers to cause a denial of service (interface queue wedge) via tunneled (1) GRE/IP, (2) IPIP, or (3) IPv6 in IPv4 packets, aka Bug ID CSCts66808.
network
low complexity
cisco CWE-399
7.8