Vulnerabilities > Cisco > High

DATE CVE VULNERABILITY TITLE RISK
2016-07-28 CVE-2016-1463 Improper Input Validation vulnerability in Cisco Firesight System Software
Cisco FireSIGHT System Software 5.3.0, 5.3.1, 5.4.0, 6.0, and 6.0.1 allows remote attackers to bypass Snort rules via crafted parameters in the header of an HTTP packet, aka Bug ID CSCuz20737.
network
low complexity
cisco CWE-20
7.5
2016-07-28 CVE-2016-1374 Improper Input Validation vulnerability in Cisco Unified Computing System Performance Manager
The web framework in Cisco Unified Computing System (UCS) Performance Manager 2.0.0 and earlier allows remote authenticated users to execute arbitrary commands via crafted parameters in a GET request, aka Bug ID CSCuy07827.
network
low complexity
cisco CWE-20
8.8
2016-07-17 CVE-2016-1448 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Webex Meetings Server 2.7.1/2.7Base
Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 2.7 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuy92706.
network
low complexity
cisco CWE-352
8.8
2016-07-15 CVE-2016-1456 Permissions, Privileges, and Access Controls vulnerability in Cisco IOS XR 6.0.0/6.0.1/6.0Base
The CLI in Cisco IOS XR 6.x through 6.0.1 allows local users to execute arbitrary OS commands in a privileged context by leveraging unspecified container access, aka Bug ID CSCuz62721.
local
low complexity
cisco CWE-264
7.8
2016-07-15 CVE-2016-1450 Improper Input Validation vulnerability in Cisco Webex Meetings Server 2.6.0/2.6.1.39
Cisco WebEx Meetings Server 2.6 allows remote authenticated users to conduct command-injection attacks via vectors related to an upload's file type, aka Bug ID CSCuy92715.
network
high complexity
cisco CWE-20
7.5
2016-07-15 CVE-2016-1446 SQL Injection vulnerability in Cisco Webex Meetings Server 2.6.0/2.6.1.39
SQL injection vulnerability in Cisco WebEx Meetings Server 2.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuy83200.
network
low complexity
cisco CWE-89
8.8
2016-07-15 CVE-2016-1426 Resource Management Errors vulnerability in Cisco IOS XR
Cisco IOS XR 5.x through 5.2.5 on NCS 6000 devices allows remote attackers to cause a denial of service (timer consumption and Route Processor reload) via crafted SSH traffic, aka Bug ID CSCux76819.
network
low complexity
cisco CWE-399
7.5
2016-07-07 CVE-2016-1443 7PK - Security Features vulnerability in Cisco AMP Threat Grid Appliance
The virtual network stack on Cisco AMP Threat Grid Appliance devices before 2.1.1 allows remote attackers to bypass a sandbox protection mechanism, and consequently obtain sensitive interprocess information or modify interprocess data, via a crafted malware sample.
network
high complexity
cisco CWE-254
8.1
2016-07-07 CVE-2016-1442 Improper Input Validation vulnerability in Cisco Prime Infrastructure 3.0/3.1
The administrative web interface in Cisco Prime Infrastructure (PI) before 3.1.1 allows remote authenticated users to execute arbitrary commands via crafted field values, aka Bug ID CSCuy96280.
network
low complexity
cisco CWE-20
8.8
2016-07-03 CVE-2016-1337 Information Exposure vulnerability in Cisco Epc3928 Firmware
Cisco EPC3928 devices allow remote attackers to obtain sensitive configuration and credential information by making requests during the early part of the boot process, related to a "Boot Information Disclosure" issue, aka Bug ID CSCux17178.
network
high complexity
cisco CWE-200
8.1