Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2015-09-14 CVE-2015-6286 Resource Management Errors vulnerability in Cisco Application Visibility and Control 15.3(3)Ja
Cisco Application Visibility and Control (AVC) 15.3(3)JA, when FlexConnect is enabled, allows remote attackers to cause a denial of service (access-point outage) via a crafted UDP packet, aka Bug ID CSCuu47016.
5.7
2015-09-14 CVE-2015-6285 Use of Externally-Controlled Format String vulnerability in Cisco Email Security Appliance 7.6.0/8.0.0
Format string vulnerability in Cisco Email Security Appliance (ESA) 7.6.0 and 8.0.0 allows remote attackers to cause a denial of service (memory overwrite or service outage) via format string specifiers in an HTTP request, aka Bug ID CSCug21497.
network
low complexity
cisco CWE-134
6.4
2015-09-05 CVE-2015-6276 Information Exposure vulnerability in Cisco Telepresence System Software IX 8.0.3
Cisco TelePresence IX5000 8.0.3 stores a private key associated with an X.509 certificate under the web root with insufficient access control, which allows remote attackers to obtain cleartext versions of HTTPS traffic or spoof devices via a direct request to the certificate directory, aka Bug ID CSCuu63501.
network
low complexity
cisco CWE-200
5.0
2015-09-04 CVE-2015-6259 Improper Input Validation vulnerability in Cisco products
The JavaServer Pages (JSP) component in Cisco Integrated Management Controller (IMC) Supervisor before 1.0.0.1 and UCS Director (formerly Cloupia Unified Infrastructure Controller) before 5.2.0.1 allows remote attackers to write to arbitrary files via crafted HTTP requests, aka Bug IDs CSCus36435 and CSCus62625.
network
low complexity
cisco CWE-20
critical
9.4
2015-09-02 CVE-2015-6277 Resource Management Errors vulnerability in Cisco products
The ARP implementation in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 5.2(1)SV3(1.4), Nexus 3000 devices 7.3(0)ZD(0.47), Nexus 4000 devices 4.1(2)E1, Nexus 9000 devices 7.3(0)ZD(0.61), and MDS 9000 devices 7.0(0)HSK(0.353) and SAN-OS NX-OS on MDS 9000 devices 7.0(0)HSK(0.353) allows remote attackers to cause a denial of service (ARP process restart) via crafted packet-header fields, aka Bug ID CSCut25292.
low complexity
cisco CWE-399
6.1
2015-09-02 CVE-2015-6274 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco ASR 1000 Series Software 15.5(3)S
The IPv4 implementation on Cisco ASR 1000 devices with software 15.5(3)S allows remote attackers to cause a denial of service (ESP QFP CPU consumption) by triggering packet fragmentation and reassembly, aka Bug ID CSCuv71273.
network
low complexity
cisco CWE-119
5.0
2015-09-02 CVE-2015-4330 OS Command Injection vulnerability in Cisco Telepresence Video Communication Server Software X8.5.2
A local file script in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to gain privileges for OS command execution via invalid parameters, aka Bug ID CSCuv10556.
local
cisco CWE-78
6.9
2015-08-31 CVE-2015-6272 Resource Management Errors vulnerability in Cisco IOS XE
Cisco IOS XE 2.1.0 through 2.2.3 and 2.3.0 on ASR 1000 devices, when NAT Application Layer Gateway is used, allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted H.323 packet, aka Bug ID CSCsx35393, CSCsx07094, and CSCsw93064.
network
low complexity
cisco CWE-399
7.8
2015-08-31 CVE-2015-6271 Resource Management Errors vulnerability in Cisco IOS XE
Cisco IOS XE 2.1.0 through 2.4.3 and 2.5.0 on ASR 1000 devices, when NAT Application Layer Gateway is used, allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted SIP packet, aka Bug IDs CSCta74749 and CSCta77008.
network
low complexity
cisco CWE-399
7.8
2015-08-31 CVE-2015-6270 Resource Management Errors vulnerability in Cisco IOS XE 2.2.1/2.2.2
Cisco IOS XE before 2.2.3 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted IPv6 packet, aka Bug ID CSCsv98555.
network
low complexity
cisco CWE-399
7.8