Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2008-06-26 CVE-2008-2061 Improper Input Validation vulnerability in Cisco Unified Communications Manager
The Computer Telephony Integration (CTI) Manager service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3c) and 6.x before 6.1(2) allows remote attackers to cause a denial of service (TSP crash) via malformed network traffic to TCP port 2748.
network
low complexity
cisco CWE-20
7.8
2008-06-18 CVE-2008-2060 Configuration vulnerability in Cisco Intrusion Prevention System 5.1/6.0
Unspecified vulnerability in Cisco Intrusion Prevention System (IPS) 5.x before 5.1(8)E2 and 6.x before 6.0(5)E2, when inline mode and jumbo Ethernet support are enabled, allows remote attackers to cause a denial of service (panic), and possibly bypass intended restrictions on network traffic, via a "specific series of jumbo Ethernet frames."
network
cisco CWE-16
7.8
2008-06-10 CVE-2008-0960 Improper Authentication vulnerability in Juniper Session and Resource Control and SRC PE
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.
network
low complexity
cisco ecos-sourceware net-snmp sun ingate juniper CWE-287
critical
10.0
2008-06-10 CVE-2008-2636 Improper Input Validation vulnerability in Cisco Linksys Wrh54G Router 1.01.03
The HTTP service on the Cisco Linksys WRH54G with firmware 1.01.03 allows remote attackers to cause a denial of service (management interface outage) or possibly execute arbitrary code via a URI that begins with a "/./" sequence, contains many instances of a "front_page" sequence, and ends with a ".asp" sequence.
network
low complexity
cisco CWE-20
7.8
2008-05-29 CVE-2008-2054 Unspecified vulnerability in Cisco Ciscoworks Common Services
Unspecified vulnerability in Cisco CiscoWorks Common Services 3.0.3 through 3.1.1 allows remote attackers to execute arbitrary code on a client machine via unknown vectors.
network
cisco
critical
9.3
2008-05-22 CVE-2008-2053 Privilege Escalation vulnerability in Cisco Unified Customer Voice Portal 4.0/4.1/7.0
Unspecified vulnerability in Cisco Unified Customer Voice Portal (CVP) 4.0.x before 4.0(2)_ES14, 4.1.x before 4.1(1)_ES11, and 7.x before 7.0(1) allows remote authenticated users with administrator role privileges to create, modify, or delete a superuser account.
network
low complexity
cisco
critical
9.0
2008-05-22 CVE-2008-1159 Denial of Service vulnerability in Cisco IOS S, IOS T and IOS XR
Multiple unspecified vulnerabilities in the SSH server in Cisco IOS 12.4 allow remote attackers to cause a denial of service (device restart) via unknown vectors, aka Bug ID (1) CSCsk42419, (2) CSCsk60020, and (3) CSCsh51293.
network
cisco
7.1
2008-05-22 CVE-2008-0536 Improper Authentication vulnerability in multiple products
Unspecified vulnerability in the SSH server in (1) Cisco Service Control Engine (SCE) 3.0.x before 3.0.7 and 3.1.x before 3.1.0, and (2) Icon Labs Iconfidant SSH before 2.3.8, allows remote attackers to cause a denial of service (management interface outage) via SSH traffic that occurs during management operations and triggers "illegal I/O operations," aka Bug ID CSCsh49563.
network
low complexity
cisco icon-labs CWE-287
7.8
2008-05-22 CVE-2008-0535 Credentials Management vulnerability in multiple products
Unspecified vulnerability in the SSH server in (1) Cisco Service Control Engine (SCE) before 3.1.6, and (2) Icon Labs Iconfidant SSH before 2.3.8, allows remote attackers to cause a denial of service (device instability) via "SSH credentials that attempt to change the authentication method," aka Bug ID CSCsm14239.
network
low complexity
cisco icon-labs CWE-255
7.8
2008-05-22 CVE-2008-0534 Improper Input Validation vulnerability in multiple products
The SSH server in (1) Cisco Service Control Engine (SCE) before 3.1.6, and (2) Icon Labs Iconfidant SSH before 2.3.8, allows remote attackers to cause a denial of service (device restart or daemon outage) via a high rate of login attempts, aka Bug ID CSCsi68582.
network
low complexity
cisco icon-labs CWE-20
7.8