Vulnerabilities > Cisco > Critical

DATE CVE VULNERABILITY TITLE RISK
2016-11-03 CVE-2016-6448 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco Meeting Server
A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system.
network
low complexity
cisco CWE-119
critical
9.8
2016-11-03 CVE-2016-6447 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco Meeting APP and Meeting Server
A vulnerability in Cisco Meeting Server and Meeting App could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system.
network
low complexity
cisco CWE-119
critical
9.8
2016-11-03 CVE-2016-6441 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco IOS XE
A vulnerability in the Transaction Language 1 (TL1) code of Cisco ASR 900 Series routers could allow an unauthenticated, remote attacker to cause a reload of, or remotely execute code on, the affected system.
network
low complexity
cisco CWE-119
critical
9.8
2016-10-28 CVE-2016-6397 Improper Authentication vulnerability in Cisco IP Interoperability and Collaboration System
A vulnerability in the interdevice communications interface of the Cisco IP Interoperability and Collaboration System (IPICS) Universal Media Services (UMS) could allow an unauthenticated, remote attacker to modify configuration parameters of the UMS and cause the system to become unavailable.
network
low complexity
cisco CWE-287
critical
9.8
2016-10-27 CVE-2016-6445 Improper Input Validation vulnerability in Cisco Meeting Server
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of the Cisco Meeting Server (CMS) before 2.0.6 and Acano Server before 1.8.18 and 1.9.x before 1.9.6 could allow an unauthenticated, remote attacker to masquerade as a legitimate user.
network
low complexity
cisco CWE-20
critical
9.1
2016-10-06 CVE-2016-1453 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco Nx-Os
Buffer overflow in the Overlay Transport Virtualization (OTV) GRE feature in Cisco NX-OS 5.0 through 7.3 on Nexus 7000 and 7700 devices allows remote attackers to execute arbitrary code via long parameters in a packet header, aka Bug ID CSCuy95701.
network
low complexity
cisco CWE-119
critical
9.8
2016-09-22 CVE-2016-6406 Permissions, Privileges, and Access Controls vulnerability in Cisco Email Security Appliance Firmware
Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on Email Security Appliance (ESA) devices, when Enrollment Client before 1.0.2-065 is installed, allows remote attackers to obtain root access via a connection to the testing/debugging interface, aka Bug ID CSCvb26017.
network
low complexity
cisco CWE-264
critical
9.8
2016-09-22 CVE-2016-6374 Improper Input Validation vulnerability in Cisco Cloud Services Platform 2100 2.0.0
Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote attackers to execute arbitrary code via a crafted dnslookup command in an HTTP request, aka Bug ID CSCuz89093.
network
low complexity
cisco CWE-20
critical
9.8
2016-09-12 CVE-2016-6394 Permissions, Privileges, and Access Controls vulnerability in Cisco Firesight System Software
Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hijack web sessions via a session identifier, aka Bug ID CSCuz80503.
network
low complexity
cisco CWE-264
critical
9.1
2016-09-02 CVE-2016-1473 Information Exposure vulnerability in Cisco Small Business 220 Series Smart Plus Switches 1.0.0.17/1.0.0.18/1.0.0.19
Cisco Small Business 220 devices with firmware before 1.0.1.1 have a hardcoded SNMP community, which allows remote attackers to read or modify SNMP objects by leveraging knowledge of this community, aka Bug ID CSCuz76216.
network
low complexity
cisco CWE-200
critical
9.8