Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2009-09-29 CVE-2009-3457 Information Exposure vulnerability in Cisco ACE web Application Firewall and ACE XML Gateway
Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive information via an HTTP request that lacks a handler, as demonstrated by (1) an OPTIONS request or (2) a crafted GET request, leading to a Message-handling Errors message containing a certain client intranet IP address, aka Bug ID CSCtb82159.
network
low complexity
cisco CWE-200
5.0
2009-09-28 CVE-2009-2873 Unspecified vulnerability in Cisco IOS
Cisco IOS 12.0 through 12.4, when IP-based tunnels and the Cisco Express Forwarding feature are enabled, allows remote attackers to cause a denial of service (device reload) via malformed packets, aka Bug ID CSCsx70889.
network
cisco
7.1
2009-09-28 CVE-2009-2872 Unspecified vulnerability in Cisco IOS
Cisco IOS 12.0 through 12.4, when IP-based tunnels and the Cisco Express Forwarding feature are enabled, allows remote attackers to cause a denial of service (device reload) via a malformed packet that is not properly handled during switching from one tunnel to a second tunnel, aka Bug IDs CSCsh97579 and CSCsq31776.
network
low complexity
cisco
6.8
2009-09-28 CVE-2009-2871 Unspecified vulnerability in Cisco IOS
Unspecified vulnerability in Cisco IOS 12.2 and 12.4, when SSLVPN sessions, SSH sessions, or IKE encrypted nonces are enabled, allows remote attackers to cause a denial of service (device reload) via a crafted encrypted packet, aka Bug ID CSCsq24002.
network
low complexity
cisco
7.8
2009-09-28 CVE-2009-2870 Unspecified vulnerability in Cisco IOS
Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when the Cisco Unified Border Element feature is enabled, allows remote attackers to cause a denial of service (device reload) via crafted SIP messages, aka Bug ID CSCsx25880.
network
low complexity
cisco
7.8
2009-09-28 CVE-2009-2869 Unspecified vulnerability in Cisco IOS
Unspecified vulnerability in Cisco IOS 12.2XNA, 12.2XNB, 12.2XNC, 12.2XND, 12.4MD, 12.4T, 12.4XZ, and 12.4YA allows remote attackers to cause a denial of service (device reload) via a crafted NTPv4 packet, aka Bug IDs CSCsu24505 and CSCsv75948.
network
low complexity
cisco
7.8
2009-09-28 CVE-2009-2868 Unspecified vulnerability in Cisco IOS
Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when certificate-based authentication is enabled for IKE, allows remote attackers to cause a denial of service (Phase 1 SA exhaustion) via crafted requests, aka Bug IDs CSCsy07555 and CSCee72997.
network
low complexity
cisco
7.8
2009-09-28 CVE-2009-2867 Unspecified vulnerability in Cisco IOS
Unspecified vulnerability in Cisco IOS 12.2XNA, 12.2XNB, 12.2XNC, 12.2XND, 12.4T, 12.4XZ, and 12.4YA, when Zone-Based Policy Firewall SIP Inspection is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted SIP transit packet, aka Bug ID CSCsr18691.
network
low complexity
cisco
7.8
2009-09-28 CVE-2009-2866 Denial of Service vulnerability in Cisco IOS H.323
Unspecified vulnerability in Cisco IOS 12.2 through 12.4 allows remote attackers to cause a denial of service (device reload) via a crafted H.323 packet, aka Bug ID CSCsz38104.
network
low complexity
cisco
7.8
2009-09-28 CVE-2009-2865 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cisco IOS and Unified Communications Manager Express
Buffer overflow in the login implementation in the Extension Mobility feature in the Unified Communications Manager Express (CME) component in Cisco IOS 12.4XW, 12.4XY, 12.4XZ, and 12.4YA allows remote attackers to execute arbitrary code or cause a denial of service via crafted HTTP requests, aka Bug ID CSCsq58779.
network
high complexity
cisco CWE-119
7.6