Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2017-10-05 CVE-2017-12266 Uncontrolled Search Path Element vulnerability in Cisco Meeting APP
A vulnerability in the routine that loads DLL files in Cisco Meeting App for Windows could allow an authenticated, local attacker to run an executable file with privileges equivalent to those of Cisco Meeting App.
local
low complexity
cisco CWE-427
4.2
2017-10-05 CVE-2017-12265 Cross-site Scripting vulnerability in Cisco Adaptive Security Appliance
A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device, aka HREF XSS.
network
low complexity
cisco CWE-79
6.1
2017-10-05 CVE-2017-12264 Improper Input Validation vulnerability in Cisco Meeting Server
A vulnerability in the Web Admin Interface of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
5.3
2017-10-05 CVE-2017-12263 Path Traversal vulnerability in Cisco License Manager 3.2.6
A vulnerability in the web interface of Cisco License Manager software could allow an unauthenticated, remote attacker to download and view files within the application that should be restricted, aka Directory Traversal.
network
low complexity
cisco CWE-22
7.5
2017-10-05 CVE-2017-12258 Cross-site Scripting vulnerability in Cisco Unified Communications Manager
A vulnerability in the web-based UI of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack.
network
low complexity
cisco CWE-79
6.1
2017-10-05 CVE-2017-12257 Cross-site Scripting vulnerability in Cisco Webex Meetings Server
A vulnerability in the web framework of Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system.
network
low complexity
cisco CWE-79
6.1
2017-10-05 CVE-2017-12256 Unspecified vulnerability in Cisco Wide Area Application Services
A vulnerability in the Akamai Connect feature of Cisco Wide Area Application Services (WAAS) Appliances could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition on an affected device.
network
low complexity
cisco
6.5
2017-10-05 CVE-2017-12246 Improper Input Validation vulnerability in Cisco Adaptive Security Appliance Software 9.4(3)/9.7(1)/9.8(0.56)
A vulnerability in the implementation of the direct authentication feature in Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause an affected device to unexpectedly reload, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
8.6
2017-10-05 CVE-2017-12245 Missing Release of Resource after Effective Lifetime vulnerability in Cisco Firepower Management Center
A vulnerability in SSL traffic decryption for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause depletion of system memory, aka a Firepower Detection Engine SSL Decryption Memory Consumption Denial of Service vulnerability.
network
low complexity
cisco CWE-772
8.6
2017-10-05 CVE-2017-12244 Improper Input Validation vulnerability in Cisco Firepower Management Center
A vulnerability in the detection engine parsing of IPv6 packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause high CPU utilization or to cause a denial of service (DoS) condition because the Snort process restarts unexpectedly.
network
low complexity
cisco CWE-20
8.6