Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2019-01-23 CVE-2019-1638 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco Webex Meetings Online and Webex Meetings Server
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system.
network
cisco CWE-119
critical
9.3
2019-01-23 CVE-2019-1637 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco Webex Meetings Online and Webex Meetings Server
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system.
network
cisco CWE-119
critical
9.3
2019-01-23 CVE-2019-1636 OS Command Injection vulnerability in Cisco Webex Teams 3.0.4533
A vulnerability in the Cisco Webex Teams client, formerly Cisco Spark, could allow an attacker to execute arbitrary commands on a targeted system.
network
cisco CWE-78
critical
9.3
2019-01-23 CVE-2018-15459 Unspecified vulnerability in Cisco Identity Services Engine 2.3(0.298)/2.5(0.1)
A vulnerability in the administrative web interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to gain additional privileges on an affected device.
network
low complexity
cisco
6.5
2019-01-23 CVE-2018-15455 Cross-site Scripting vulnerability in Cisco Identity Services Engine 2.2(0.910)/2.3(0.905)/2.4(0.903)
A vulnerability in the logging component of Cisco Identity Services Engine could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks.
network
cisco CWE-79
4.3
2019-01-23 CVE-2018-0187 Information Exposure vulnerability in Cisco Identity Services Engine 2.4(0.901.1)/2.4(0.901)
A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain confidential information for privileged accounts.
network
low complexity
cisco CWE-200
4.0
2019-01-15 CVE-2018-15463 Cross-site Scripting vulnerability in Cisco Identity Services Engine Software 2.4(0.357)
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based interface.
network
cisco CWE-79
4.3
2019-01-15 CVE-2018-15440 Cross-site Scripting vulnerability in Cisco Identity Services Engine Software 2.4(0.357)
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of an affected system.
network
cisco CWE-79
4.3
2019-01-11 CVE-2018-15467 Cross-site Scripting vulnerability in Cisco Telepresence Management Suite 15.7
A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device.
network
cisco CWE-79
4.3
2019-01-11 CVE-2018-15466 Missing Authentication for Critical Function vulnerability in Cisco Policy Suite for Mobile 12.0.0
A vulnerability in the Graphite web interface of the Policy and Charging Rules Function (PCRF) of Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to access the Graphite web interface.
network
cisco CWE-306
4.3