Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2016-08-08 CVE-2016-1466 Resource Management Errors vulnerability in Cisco Unified Communications Manager IM and Presence Service
Cisco Unified Communications Manager IM and Presence Service 9.1(1) SU6, 9.1(1) SU6a, 9.1(1) SU7, 10.5(2) SU2, 10.5(2) SU2a, 11.0(1) SU1, and 11.5(1) allows remote attackers to cause a denial of service (sipd process restart) via crafted headers in a SIP packet, aka Bug ID CSCva39072.
network
low complexity
cisco CWE-399
7.5
2016-08-08 CVE-2016-1430 Improper Input Validation vulnerability in Cisco products
Cisco RV180 and RV180W devices allow remote authenticated users to execute arbitrary commands as root via a crafted HTTP request, aka Bug ID CSCuz48592.
network
low complexity
cisco CWE-20
8.8
2016-08-08 CVE-2016-1429 Path Traversal vulnerability in Cisco products
Directory traversal vulnerability in the web interface on Cisco RV180 and RV180W devices allows remote attackers to read arbitrary files via a crafted HTTP request, aka Bug ID CSCuz43023.
network
low complexity
cisco CWE-22
7.5
2016-08-08 CVE-2015-6397 Improper Authentication vulnerability in Cisco products
Cisco RV110W, RV130W, and RV215W devices have an incorrect RBAC configuration for the default account, which allows remote authenticated users to obtain root access via a login session with that account, aka Bug IDs CSCuv90139, CSCux58175, and CSCux73557.
network
low complexity
cisco CWE-287
8.8
2016-08-08 CVE-2015-6396 OS Command Injection vulnerability in Cisco products
The CLI command parser on Cisco RV110W, RV130W, and RV215W devices allows local users to execute arbitrary shell commands as an administrator via crafted parameters, aka Bug IDs CSCuv90134, CSCux58161, and CSCux73567.
local
low complexity
cisco CWE-78
7.8
2016-08-01 CVE-2016-1461 Improper Input Validation vulnerability in Cisco Asyncos
Cisco AsyncOS on Email Security Appliance (ESA) devices through 9.7.0-125 allows remote attackers to bypass malware detection via a crafted attachment in an e-mail message, aka Bug ID CSCuz14932.
network
low complexity
cisco CWE-20
7.5
2016-07-28 CVE-2016-1467 Resource Management Errors vulnerability in Cisco Videoscape Session Resource Manager
Cisco Videoscape Session Resource Manager (VSRM) allows remote attackers to cause a denial of service (device restart) by sending a traffic flood to upstream devices, aka Bug ID CSCva01813.
low complexity
cisco CWE-399
6.5
2016-07-28 CVE-2016-1465 Resource Management Errors vulnerability in Cisco Nx-Os
Cisco Nexus 1000v Application Virtual Switch (AVS) devices before 5.2(1)SV3(1.5i) allow remote attackers to cause a denial of service (ESXi hypervisor crash and purple screen) via a crafted Cisco Discovery Protocol packet that triggers an out-of-bounds memory access, aka Bug ID CSCuw57985.
low complexity
cisco CWE-399
6.5
2016-07-28 CVE-2016-1463 Improper Input Validation vulnerability in Cisco Firesight System Software
Cisco FireSIGHT System Software 5.3.0, 5.3.1, 5.4.0, 6.0, and 6.0.1 allows remote attackers to bypass Snort rules via crafted parameters in the header of an HTTP packet, aka Bug ID CSCuz20737.
network
low complexity
cisco CWE-20
7.5
2016-07-28 CVE-2016-1462 Cross-site Scripting vulnerability in Cisco Prime Service Catalog 11.0Base
Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Prime Service Catalog (PSC) 11.0 allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCuz63795.
network
low complexity
cisco CWE-79
6.1