Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2013-06-27 CVE-2013-3386 Resource Management Errors vulnerability in Cisco Ironport Asyncos
The IronPort Spam Quarantine (ISQ) component in the web framework in IronPort AsyncOS on Cisco Email Security Appliance devices before 7.1.5-106 and 7.3, 7.5, and 7.6 before 7.6.3-019 and Content Security Management Appliance devices before 7.9.1-102 and 8.0 before 8.0.0-404 allows remote attackers to cause a denial of service (service crash or hang) via a high rate of TCP connection attempts, aka Bug IDs CSCzv25573 and CSCzv81712.
network
low complexity
cisco CWE-399
7.8
2013-06-27 CVE-2013-3385 Resource Management Errors vulnerability in Cisco Ironport Asyncos
The management GUI in the web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-602; Email Security Appliance devices before 7.1.5-106 and 7.3, 7.5, and 7.6 before 7.6.3-019; and Content Security Management Appliance devices before 7.9.1-102 and 8.0 before 8.0.0-404 allows remote attackers to cause a denial of service (system hang) via a series of (1) HTTP or (2) HTTPS requests to a management interface, aka Bug IDs CSCzv58669, CSCzv63329, and CSCzv78669.
network
low complexity
cisco CWE-399
7.8
2013-06-27 CVE-2013-3384 Code Injection vulnerability in Cisco Ironport Asyncos
The web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-550; Email Security Appliance devices before 7.1.5-104, 7.3 before 7.3.2-026, 7.5 before 7.5.2-203, and 7.6 before 7.6.3-019; and Content Security Management Appliance devices before 7.2.2-110, 7.7 before 7.7.0-213, and 7.8 and 7.9 before 7.9.1-102 allows remote authenticated users to execute arbitrary commands via crafted command-line input in a URL, aka Bug IDs CSCzv85726, CSCzv44633, and CSCzv24579.
network
low complexity
cisco CWE-94
critical
9.0
2013-06-27 CVE-2013-3383 Code Injection vulnerability in Cisco Ironport Asyncos 7.5/7.7
The web framework in IronPort AsyncOS on Cisco Web Security Appliance devices before 7.1.3-013, 7.5 before 7.5.0-838, and 7.7 before 7.7.0-550 allows remote authenticated users to execute arbitrary commands via crafted command-line input in a URL sent over IPv4, aka Bug ID CSCzv69294.
network
low complexity
cisco CWE-94
critical
9.0
2013-06-26 CVE-2013-3398 Information Exposure vulnerability in Cisco Prime Central FOR Hosted Collaboration Solution
The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance provides different responses to requests for arbitrary pathnames depending on whether the pathname exists, which allows remote attackers to enumerate directories and files via a series of crafted requests, aka Bug ID CSCuh64574.
network
low complexity
cisco CWE-200
5.0
2013-06-26 CVE-2013-3397 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Unified Communications Manager
Cross-site request forgery (CSRF) vulnerability in the Unified Serviceability component in Cisco Unified Communications Manager (CUCM) allows remote attackers to hijack the authentication of arbitrary users for requests that perform Unified Serviceability actions, aka Bug ID CSCuh10298.
network
cisco CWE-352
6.8
2013-06-26 CVE-2013-3396 Cross-Site Scripting vulnerability in Cisco Content Security Management Appliance
Cross-site scripting (XSS) vulnerability in the web framework in Cisco Content Security Management on Security Management Appliance (SMA) devices allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuh24749.
network
cisco CWE-79
4.3
2013-06-26 CVE-2013-3393 Improper Input Validation vulnerability in Cisco Jabber and Virtualization Experience Media Engine
The Precision Video Engine component in Cisco Jabber for Windows and Cisco Virtualization Experience Media Engine allows remote attackers to cause a denial of service (process crash and call disconnection) via crafted RTP packets, aka Bug IDs CSCuh60706 and CSCue21117.
network
low complexity
cisco CWE-20
5.0
2013-06-26 CVE-2013-3382 Improper Input Validation vulnerability in Cisco Adaptive Security Appliance
The Next-Generation Firewall (aka NGFW, formerly CX Context-Aware Security) module 9.x before 9.1.1.9 and 9.1.2.x before 9.1.2.12 for Cisco Adaptive Security Appliances (ASA) devices allows remote attackers to cause a denial of service (device reload or traffic-processing outage) via fragmented (1) IPv4 or (2) IPv6 traffic, aka Bug ID CSCue88387.
network
low complexity
cisco CWE-20
7.8
2013-06-21 CVE-2013-3392 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Webex Social
Multiple cross-site request forgery (CSRF) vulnerabilities in Cisco WebEx Social allow remote attackers to hijack the authentication of arbitrary users via unspecified vectors, aka Bug IDs CSCuh10405 and CSCuh10355.
network
cisco CWE-352
4.3