Vulnerabilities > Cisco

DATE CVE VULNERABILITY TITLE RISK
2008-03-27 CVE-2008-1152 Resource Management Errors vulnerability in Cisco IOS and IOS
The data-link switching (DLSw) component in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device restart or memory consumption) via crafted (1) UDP port 2067 or (2) IP protocol 91 packets.
network
low complexity
cisco CWE-399
7.8
2008-03-27 CVE-2008-1151 Resource Management Errors vulnerability in Cisco IOS
Memory leak in the virtual private dial-up network (VPDN) component in Cisco IOS before 12.3 allows remote attackers to cause a denial of service (memory consumption) via a series of PPTP sessions, related to "dead memory" that remains allocated after process termination, aka bug ID CSCsj58566.
network
cisco CWE-399
7.1
2008-03-27 CVE-2008-1150 Resource Management Errors vulnerability in Cisco IOS
The virtual private dial-up network (VPDN) component in Cisco IOS before 12.3 allows remote attackers to cause a denial of service (resource exhaustion) via a series of PPTP sessions, related to the persistence of interface descriptor block (IDB) data structures after process termination, aka bug ID CSCdv59309.
network
cisco CWE-399
7.1
2008-03-27 CVE-2008-1156 Information Exposure vulnerability in Cisco IOS and IOS
Unspecified vulnerability in the Multicast Virtual Private Network (MVPN) implementation in Cisco IOS 12.0, 12.2, 12.3, and 12.4 allows remote attackers to create "extra multicast states on the core routers" via a crafted Multicast Distribution Tree (MDT) Data Join message.
network
high complexity
cisco CWE-200
5.1
2008-03-27 CVE-2008-1153 Denial Of Service vulnerability in Cisco IOS and IOS
Cisco IOS 12.1, 12.2, 12.3, and 12.4, with IPv4 UDP services and the IPv6 protocol enabled, allows remote attackers to cause a denial of service (device crash and possible blocked interface) via a crafted IPv6 packet to the device.
network
cisco
7.1
2008-03-27 CVE-2008-0537 Unspecified vulnerability in Cisco Route Switch Processor and Supervisor Engine
Unspecified vulnerability in the Supervisor Engine 32 (Sup32), Supervisor Engine 720 (Sup720), and Route Switch Processor 720 (RSP720) for multiple Cisco products, when using Multi Protocol Label Switching (MPLS) VPN and OSPF sham-link, allows remote attackers to cause a denial of service (blocked queue, device restart, or memory leak) via unknown vectors.
network
cisco
7.1
2008-03-14 CVE-2008-1157 Improper Input Validation vulnerability in Cisco Ciscoworks Internetwork Performance Monitor 2.6
Cisco CiscoWorks Internetwork Performance Monitor (IPM) 2.6 creates a process that executes a command shell and listens on a randomly chosen TCP port, which allows remote attackers to execute arbitrary commands.
network
low complexity
cisco CWE-20
critical
10.0
2008-03-14 CVE-2008-0533 Cross-Site Scripting vulnerability in Cisco products
Multiple cross-site scripting (XSS) vulnerabilities in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to inject arbitrary web script or HTML via an argument located immediately after the Help argument, and possibly unspecified other vectors.
network
cisco CWE-79
4.3
2008-03-14 CVE-2008-0532 Buffer Errors vulnerability in Cisco products
Multiple buffer overflows in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to execute arbitrary code via a long argument located immediately after the Logout argument, and possibly unspecified other vectors.
network
low complexity
cisco CWE-119
critical
10.0
2008-03-03 CVE-2008-1113 Information Exposure vulnerability in Vocera Communications Vocera Communications Badge
Cisco Unified Wireless IP Phone 7921, when using Protected Extensible Authentication Protocol (PEAP), does not validate server certificates, which allows remote wireless access points to steal hashed passwords and conduct man-in-the-middle (MITM) attacks.
network
low complexity
cisco vocera-communications CWE-200
7.8