Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2013-04-25 CVE-2013-1178 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cisco products
Multiple buffer overflows in the Cisco Discovery Protocol (CDP) implementation in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(4) and 6.x before 6.1(1), Nexus 5000 and 5500 devices 4.x and 5.x before 5.1(3)N1(1), Nexus 4000 devices before 4.1(2)E1(1h), Nexus 3000 devices 5.x before 5.0(3)U3(1), Nexus 1000V devices 4.x before 4.2(1)SV1(5.1), MDS 9000 devices 4.x and 5.x before 5.2(4), Unified Computing System (UCS) 6100 and 6200 devices before 2.0(2m), and Connected Grid Router (CGR) 1000 devices before CG4(1) allow remote attackers to execute arbitrary code via malformed CDP packets, aka Bug IDs CSCtu10630, CSCtu10551, CSCtu10550, CSCtw56581, CSCtu10548, CSCtu10544, and CSCuf61275.
low complexity
cisco CWE-119
8.3
2013-04-24 CVE-2013-1217 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cisco IOS
The generic input/output control implementation in Cisco IOS does not properly manage buffers, which allows remote authenticated users to cause a denial of service (device reload) by sending many SNMP requests at the same time, aka Bug ID CSCub41105.
network
low complexity
cisco CWE-119
6.8
2013-04-24 CVE-2013-1214 Permissions, Privileges, and Access Controls vulnerability in Cisco Unified Contact Center Express Editor Software
The scripts editor in Cisco Unified Contact Center Express (aka Unified CCX) does not properly manage privileges for anonymous logins, which allows remote attackers to read arbitrary scripts by visiting the scripts repository directory, aka Bug ID CSCuf77546.
network
low complexity
cisco CWE-264
5.0
2013-04-18 CVE-2013-1177 SQL Injection vulnerability in Cisco Network Admission Control Manager and Server System Software
SQL injection vulnerability in Cisco Network Admission Control (NAC) Manager before 4.8.3.1 and 4.9.x before 4.9.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCub23095.
network
low complexity
cisco CWE-89
7.5
2013-04-18 CVE-2013-1176 Improper Input Validation vulnerability in Cisco products
The DSP card on Cisco TelePresence MCU 4500 and 4501 devices before 4.3(2.30), TelePresence MCU MSE 8510 devices before 4.3(2.30), and TelePresence Server before 2.3(1.55) does not properly validate H.264 data, which allows remote attackers to cause a denial of service (device reload) via crafted RTP packets in a (1) SIP session or (2) H.323 session, aka Bug IDs CSCuc11328 and CSCub05448.
network
cisco CWE-20
7.1
2013-04-16 CVE-2013-1197 Improper Input Validation vulnerability in Cisco Unified Presence
The XML parser in the server in Cisco Unified Presence (CUP) allows remote authenticated users to cause a denial of service (jabberd daemon crash) via crafted XML content in an XMPP message, aka Bug ID CSCue13912.
network
low complexity
cisco CWE-20
6.8
2013-04-16 CVE-2013-1187 Improper Input Validation vulnerability in Cisco Jabber Extensible Communications Platform
The Connection Manager in Cisco Jabber Extensible Communications Platform (aka Jabber XCP) does not properly validate login data, which allows remote attackers to cause a denial of service (service crash) by sending a series of malformed login packets, aka Bug ID CSCts76762.
network
low complexity
cisco CWE-20
5.0
2013-04-16 CVE-2012-5415 Race Condition vulnerability in Cisco products
Race condition on Cisco Adaptive Security Appliances (ASA) devices allows remote attackers to cause a denial of service (CPU consumption or device reload) by establishing multiple connections, leading to improper handling of hash lookups for secondary flows, aka Bug IDs CSCue31622 and CSCuc71272.
network
high complexity
cisco CWE-362
5.4
2013-04-11 CVE-2013-2779 Improper Input Validation vulnerability in Cisco products
Cisco IOS XE 3.4 before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Services Routers (ASR) does not properly implement the Cisco Multicast Leaf Recycle Elimination (MLRE) feature, which allows remote attackers to cause a denial of service (card reload) via fragmented IPv6 MVPN (aka MVPNv6) packets, aka Bug ID CSCub34945, a different vulnerability than CVE-2013-1164.
network
low complexity
cisco CWE-20
7.8
2013-04-11 CVE-2013-1189 Improper Input Validation vulnerability in Cisco Ubr10012
Cisco Universal Broadband (aka uBR) 10000 series routers, when an IPv4/IPv6 dual-stack modem is used, allow remote attackers to cause a denial of service (routing-engine reload) via unspecified changes to IP address assignments, aka Bug ID CSCue15313.
5.7