Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2012-09-16 CVE-2012-3899 Resource Management Errors vulnerability in Cisco products
sensorApp on Cisco IPS 4200 series sensors 6.0, 6.2, and 7.0 does not properly allocate memory, which allows remote attackers to cause a denial of service (memory corruption and process crash, and traffic-inspection outage) via network traffic, aka Bug ID CSCtn23051.
network
low complexity
cisco CWE-399
5.0
2012-09-16 CVE-2012-3895 Denial-Of-Service vulnerability in IOS
Cisco IOS 15.0 through 15.3 allows remote authenticated users to cause a denial of service (device crash) via an MVPNv6 update, aka Bug ID CSCty89224.
network
cisco
6.3
2012-09-16 CVE-2012-3893 Denial-Of-Service vulnerability in Cisco IOS 15.2/15.3
The FlexVPN implementation in Cisco IOS 15.2 and 15.3 allows remote authenticated users to cause a denial of service (spoke crash) via spoke-to-spoke traffic, aka Bug ID CSCtz02622.
network
cisco
6.3
2012-09-16 CVE-2012-3096 Denial-Of-Service vulnerability in Cisco Unity Connection 7.1/8.0/8.5
Cisco Unity Connection (UC) 7.1, 8.0, and 8.5 allows remote authenticated users to cause a denial of service (resource consumption and administration outage) via extended use of the product, aka Bug ID CSCtd79132.
network
low complexity
cisco
4.0
2012-09-16 CVE-2012-3094 Information Exposure vulnerability in Cisco Anyconnect Secure Mobility Client 3.1.0
The VPN downloader in the download_install component in Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495 on Linux accepts arbitrary X.509 server certificates without user interaction, which allows remote attackers to obtain sensitive information via vectors involving an invalid certificate, aka Bug ID CSCua11967.
network
low complexity
cisco linux CWE-200
5.0
2012-09-16 CVE-2012-3088 Remote Security vulnerability in Cisco Anyconnect Secure Mobility Client 3.1.0/3.2.0
Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495, and 3.2.x, does not check whether an HTTP request originally contains ScanSafe headers, which allows remote attackers to have an unspecified impact via a crafted request, aka Bug ID CSCua13166.
network
cisco
critical
9.3
2012-09-16 CVE-2012-3079 Resource Management Errors vulnerability in Cisco IOS 12.2
Cisco IOS 12.2 allows remote attackers to cause a denial of service (CPU consumption) by establishing many IPv6 neighbors, aka Bug ID CSCtn78957.
network
low complexity
cisco CWE-399
7.8
2012-09-16 CVE-2012-3060 Resource Management Errors vulnerability in Cisco Unity Connection 8.6/9.0/9.5
Cisco Unity Connection (UC) 8.6, 9.0, and 9.5 allows remote attackers to cause a denial of service (CPU consumption) via malformed UDP packets, aka Bug ID CSCtz76269.
network
low complexity
cisco CWE-399
7.8
2012-09-16 CVE-2012-3052 Unspecified vulnerability in Cisco VPN Client
Untrusted search path vulnerability in Cisco VPN Client 5.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka Bug ID CSCua28747.
local
cisco
6.9
2012-09-16 CVE-2012-3051 Remote Denial of Service vulnerability in Cisco Nexus 7000 Series Switches NX-OS
Cisco NX-OS 5.2 and 6.1 on Nexus 7000 series switches allows remote attackers to cause a denial of service (process crash or packet loss) via a large number of ARP packets, aka Bug ID CSCtr44822.
low complexity
cisco
6.1