Vulnerabilities > Cisco > PIX Firewall Software > 6.1.3

DATE CVE VULNERABILITY TITLE RISK
2004-11-23 CVE-2004-0081 OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool. 5.0
2004-11-23 CVE-2004-0079 NULL Pointer Dereference vulnerability in multiple products
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.
7.5
2004-01-05 CVE-2003-1003 Improper Input Validation vulnerability in Cisco PIX Firewall and PIX Firewall Software
Cisco PIX firewall 5.x.x, and 6.3.1 and earlier, allows remote attackers to cause a denial of service (crash and reload) via an SNMPv3 message when snmp-server is set.
network
low complexity
cisco CWE-20
7.8
2003-12-01 CVE-2003-0851 Remote Denial Of Service vulnerability in OpenSSL ASN.1 Large Recursion
OpenSSL 0.9.6k allows remote attackers to cause a denial of service (crash via large recursion) via malformed ASN.1 sequences.
network
low complexity
cisco openssl
5.0
2002-12-31 CVE-2002-2140 Buffer Overrun vulnerability in Cisco PIX TACACS+/RADIUS HTTP Proxy
Buffer overflow in Cisco PIX Firewall 5.2.x to 5.2.8, 6.0.x to 6.0.3, 6.1.x to 6.1.3, and 6.2.x to 6.2.1 allows remote attackers to cause a denial of service via HTTP traffic authentication using (1) TACACS+ or (2) RADIUS.
network
low complexity
cisco
5.0
2002-12-31 CVE-2002-2139 Unspecified vulnerability in Cisco PIX Firewall Software
Cisco PIX Firewall 6.0.3 and earlier, and 6.1.x to 6.1.3, do not delete the duplicate ISAKMP SAs for a user's VPN session, which allows local users to hijack a session via a man-in-the-middle attack.
network
low complexity
cisco
6.4