Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2010-03-05 CVE-2010-0572 Information Exposure vulnerability in Cisco Digital Media Manager
Cisco Digital Media Manager (DMM) before 5.2 allows remote authenticated users to discover Cisco Digital Media Player credentials via vectors related to reading a (1) error log or (2) stack trace, aka Bug ID CSCtc46050.
network
high complexity
cisco CWE-200
7.1
2010-03-05 CVE-2010-0571 Permissions, Privileges, and Access Controls vulnerability in Cisco Digital Media Manager
Unspecified vulnerability in Cisco Digital Media Manager (DMM) 5.0.x and 5.1.x allows remote authenticated users to gain privileges via unknown vectors, and consequently execute arbitrary code via a crafted web application, aka Bug ID CSCtc46008.
network
cisco CWE-264
8.5
2010-03-05 CVE-2010-0570 Credentials Management vulnerability in Cisco Digital Media Manager
Cisco Digital Media Manager (DMM) 5.0.x and 5.1.x has a default password for the Tomcat administration account, which makes it easier for remote attackers to execute arbitrary code via a crafted web application, aka Bug ID CSCta03378.
network
low complexity
cisco CWE-255
critical
10.0
2010-03-05 CVE-2010-0592 Denial of Service vulnerability in Cisco Unified Communications Manager CTI Manager Service
The CTI Manager service in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x before 4.3(2)sr1a, 6.x before 6.1(3), 7.0x before 7.0(2), 7.1x before 7.1(2), and 8.x before 8.0(1) allows remote attackers to cause a denial of service (service failure) via a malformed message, aka Bug ID CSCsu31800.
network
low complexity
cisco
7.8
2010-03-05 CVE-2010-0591 Denial of Service vulnerability in Cisco Unified Communications Manager SIP Message (CVE-2010-0591)
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.x before 7.1(3b)SU2, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP REG message, related to an overflow of the Telephone-URL field, aka Bug ID CSCtc62362.
network
low complexity
cisco
7.8
2010-03-05 CVE-2010-0590 Denial of Service vulnerability in Cisco Unified Communications Manager SIP Message (CVE-2010-0590)
The CMSIPUtility component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.x before 7.1(3a)su1 and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP Register message, aka Bug ID CSCtc37188.
network
low complexity
cisco
7.8
2010-03-05 CVE-2010-0588 Denial of Service vulnerability in Cisco Unified Communications Manager SCCP (CVE-2010-0588)
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.x before 7.1(3a)su1, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SCCP (1) RegAvailableLines or (2) FwdStatReq message with an invalid Line number, aka Bug ID CSCtc47823.
network
low complexity
cisco
7.8
2010-03-05 CVE-2010-0587 Denial of Service vulnerability in Cisco Unified Communications Manager SCCP (CVE-2010-0587)
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x before 4.3(2)SR2, 6.x before 6.1(5), 7.x before 7.1(3a)su1, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SCCP StationCapabilitiesRes message with an invalid MaxCap field, aka Bug ID CSCtc38985.
network
low complexity
cisco
7.8
2010-02-23 CVE-2010-0148 Remote Denial of Service vulnerability in Cisco Security Agent 5.2
Unspecified vulnerability in Cisco Security Agent 5.2 before 5.2.0.285, when running on Linux, allows remote attackers to cause a denial of service (kernel panic) via "a series of TCP packets." Per: http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1910d.shtml Only Cisco Security Agent release 5.2 for Linux, either managed or standalone, are affected by the DoS vulnerability (the Windows version is not affected). The Linux version of standalone agents are installed in the following products: * Cisco Unified Communications Manager (CallManager) * IPCC Express * IP Interactive Voice Response (IP IVR) * Cisco Unified Meeting Place * Cisco Personal Assistant (PA) * Cisco Unity Connection Note: The Sun Solaris version of the Cisco Security Agent is not affected by these vulnerabilities.
network
low complexity
cisco linux
7.8
2010-02-23 CVE-2010-0147 SQL Injection vulnerability in Cisco Security Agent 5.1/5.2/6.0
SQL injection vulnerability in the Management Center for Cisco Security Agents 5.1 before 5.1.0.117, 5.2 before 5.2.0.296, and 6.0 before 6.0.1.132 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
cisco CWE-89
6.5