Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2011-02-03 CVE-2011-0354 Credentials Management vulnerability in Cisco products
The default configuration of Cisco Tandberg C Series Endpoints, and Tandberg E and EX Personal Video units, with software before TC4.0.0 has a blank password for the root account, which makes it easier for remote attackers to obtain access via an unspecified login method.
network
low complexity
cisco CWE-255
critical
10.0
2011-02-02 CVE-2010-3270 Buffer Errors vulnerability in Cisco Webex Meeting Center 27.0
Stack-based buffer overflow in Cisco WebEx Meeting Center T27LB before SP21 EP3 and T27LC before SP22 allows user-assisted remote authenticated users to execute arbitrary code by providing a crafted .atp file and then disconnecting from a meeting.
network
high complexity
cisco CWE-119
6.8
2011-02-02 CVE-2010-3269 Buffer Errors vulnerability in Cisco products
Multiple stack-based buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to execute arbitrary code via a crafted (1) .wrf or (2) .arf file, related to use of a function pointer in a callback mechanism.
network
cisco CWE-119
critical
9.3
2011-02-02 CVE-2010-3044 Buffer Errors vulnerability in Cisco products
Multiple buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted (1) .wrf or (2) .arf file, related to atas32.dll, a different vulnerability than CVE-2010-3041, CVE-2010-3042, and CVE-2010-3043.
network
cisco CWE-119
critical
9.3
2011-02-02 CVE-2010-3043 Buffer Errors vulnerability in Cisco products
Multiple buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted (1) .wrf or (2) .arf file, a different vulnerability than CVE-2010-3041, CVE-2010-3042, and CVE-2010-3044.
network
cisco CWE-119
critical
9.3
2011-02-02 CVE-2010-3042 Buffer Errors vulnerability in Cisco products
Multiple buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted (1) .wrf or (2) .arf file, a different vulnerability than CVE-2010-3041, CVE-2010-3043, and CVE-2010-3044.
network
cisco CWE-119
critical
9.3
2011-02-02 CVE-2010-3041 Buffer Errors vulnerability in Cisco products
Multiple buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted (1) .wrf or (2) .arf file, related to atas32.dll, a different vulnerability than CVE-2010-3042, CVE-2010-3043, and CVE-2010-3044.
network
cisco CWE-119
critical
9.3
2011-01-28 CVE-2011-0350 Denial of Service vulnerability in Cisco Content Services Gateway Malformed TCP Packet (CVE-2011-0350)
Unspecified vulnerability in Cisco IOS 12.4(24)MD before 12.4(24)MD2 on the Cisco Content Services Gateway Second Generation (aka CSG2) allows remote attackers to cause a denial of service (device hang or reload) via crafted TCP packets, aka Bug ID CSCth41891, a different vulnerability than CVE-2011-0349.
network
low complexity
cisco
7.8
2011-01-28 CVE-2011-0349 Denial of Service vulnerability in Cisco Content Services Gateway Malformed TCP Packet (CVE-2011-0349)
Unspecified vulnerability in Cisco IOS 12.4(24)MD before 12.4(24)MD2 on the Cisco Content Services Gateway Second Generation (aka CSG2) allows remote attackers to cause a denial of service (device hang or reload) via crafted TCP packets, aka Bug ID CSCth17178, a different vulnerability than CVE-2011-0350.
network
low complexity
cisco
7.8
2011-01-28 CVE-2011-0348 Permissions, Privileges, and Access Controls vulnerability in Cisco IOS
Cisco IOS 12.4(11)MD, 12.4(15)MD, 12.4(22)MD, 12.4(24)MD before 12.4(24)MD3, 12.4(22)MDA before 12.4(22)MDA5, and 12.4(24)MDA before 12.4(24)MDA3 on the Cisco Content Services Gateway Second Generation (aka CSG2) allows remote attackers to bypass intended access restrictions and intended billing restrictions by sending HTTP traffic to a restricted destination after sending HTTP traffic to an unrestricted destination, aka Bug ID CSCtk35917.
network
low complexity
cisco CWE-264
6.4