Vulnerabilities > Cisco > Critical

DATE CVE VULNERABILITY TITLE RISK
2003-03-31 CVE-2002-1558 Unspecified vulnerability in Cisco Optical Networking Systems Software
Cisco ONS15454 and ONS15327 running ONS before 3.4 have an account for the VxWorks Operating System in the TCC, TCC+ and XTC that cannot be changed or disabled, which allows remote attackers to gain privileges by connecting to the account via Telnet.
network
low complexity
cisco
critical
10.0
2002-12-23 CVE-2002-1360 Improper Input Validation vulnerability in multiple products
Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to interactions with the use of null-terminated strings as implemented using languages such as C, as demonstrated by the SSHredder SSH protocol test suite.
10.0
2002-12-23 CVE-2002-1359 Improper Input Validation vulnerability in multiple products
Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol test suite.
10.0
2002-12-23 CVE-2002-1358 Improper Input Validation vulnerability in multiple products
Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.
10.0
2002-12-23 CVE-2002-1357 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.
10.0
2000-12-19 CVE-2000-0945 Unspecified vulnerability in Cisco Catalyst 3500 XL
The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing the /exec/ directory.
network
low complexity
cisco
critical
10.0
2000-12-11 CVE-2000-1055 Unspecified vulnerability in Cisco Secure Access Control Server 2.1/2.3(3)/2.4(2)
Buffer overflow in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large TACACS+ packet.
network
low complexity
cisco
critical
10.0
2000-12-11 CVE-2000-1054 Unspecified vulnerability in Cisco Secure Access Control Server 2.1/2.3(3)/2.4(2)
Buffer overflow in CSAdmin module in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large packet.
network
low complexity
cisco
critical
10.0
1999-06-10 CVE-1999-0775 Unspecified vulnerability in Cisco IOS 11.2(14)Gs2/11.2(15)G
Cisco Gigabit Switch routers running IOS allow remote attackers to forward unauthorized packets due to improper handling of the "established" keyword in an access list.
network
low complexity
cisco
critical
10.0